Details
-
Technical task
-
Status: Closed (View Workflow)
-
Major
-
Resolution: Fixed
-
None
-
None
Description
When the files in the https://github.com/MariaDB/governance/, lists/ subdirectory are modified into the main branch trigger an action to update the relevant github teams.
The plan for the modification is as follows:
Have a github action that:
- triggers when the files in lists/** are updated
- appends the special token from a repository secret called TEAM_SYNC_TOKEN that allows it to read and write group members into GH_TOKEN .
- reads the files from the repo and extracts the desired list of github logins from these
- for each login in the desired list not present in the github team do add it to the team
- for each member in the github team not in the desired list remove it from the team
- keep vuvova and gkodinov to the github teams no matter what.
Unfortunately the Members permission that can be granted to a PAT (https://github.com/settings/personal-access-tokens/new) is not granular enough and allows editing of ALL teams the user that has generated it can access. Granting that to all MariaDB organization members might be a risk even if generated by gkodinov.