Open jorydotcom opened 2 years ago
My 2c... this policy should cover, at minimum, the following aspects:
I'm working on this - first steps are converting repo access to be all team-based instead of individual, and then to use automated tooling so readme lists are kept up to date automatically.
Once that's done, then I'll tackle the bigger question of who should have what access, which is what I think this issue deals with.
We need to define & document access/permissions for leads and participants in OpenSSF working groups and their repos. This includes policy questions (like enforcing 2FA and adding apps).