Opened 6 months ago

Closed 3 months ago

Last modified 12 days ago

#3298 closed task (fixed)

Clean up list of GitHub OSGeo organization members with "owner" role

Reported by: neteler Owned by: sac-tickets@…
Priority: critical Milestone: Unplanned
Component: SysAdmin Keywords: GitHub
Cc:

Description (last modified by neteler)

We have a surprisingly long list of OSGeo Github organization members with "owner" role. Some of them (seem to) have left OSGeo many years ago, hence it becomes a security issue:

https://github.com/orgs/OSGeo/people?query=role%3Aowner

Suggestion: cleanup up this list and selectively downgrade their role to e.g. member since "owners" could even delete the entire OSGeo organization.

Some observations:

  • one member does not even have 2FA activated. -> no-go
  • some members are out of OSGeo for even a decade? -> downgrade or remove

Question: who decides about who is "owner", the board? --> https://wiki.osgeo.org/wiki/Board_Meeting_2024-12-30

Change History (6)

comment:1 by robe, 6 months ago

I'm unclear who decides on this. I would assume the board is as good as any or the owners of OSGeo github org.

At anyrate I can't see anyone arguing that people who haven't been involved in OSGeo for many years should be owners. I would go ahead and remove them, perhaps note on this ticket who is being removed so people if they are paying attention can ask to be put back.

comment:2 by kalxas, 6 months ago

I agree we need to review this list. Let's bring it up in the next board meeting, perhaps we need a policy.

comment:3 by neteler, 4 months ago

Description: modified (diff)
Priority: normalcritical
Summary: Clean up list of OSGeo GitHub repo members with "owner" roleClean up list of GitHub OSGeo organization members with "owner" role

comment:5 by neteler, 3 months ago

Resolution: fixed
Status: newclosed

The number has been reduced to 20 members.

comment:6 by wenzeslaus, 12 days ago

Any idea if a policy has been created?

The board meeting minutes say:

ACTION: All to review the list and make a policy draft

And the following meeting minutes say:

Number of owners has already been reduced. Issue fixed.

I didn't find further mentions of this in the following meetings.

Even without a policy, I must say I'm glad to see the immediate situation resolved.

Note: See TracTickets for help on using tickets.