Details

    • Technical task
    • Status: Closed (View Workflow)
    • Major
    • Resolution: Fixed
    • None
    • N/A
    • Github
    • None

    Description

      When the files in the https://github.com/MariaDB/governance/, lists/ subdirectory are modified into the main branch trigger an action to update the relevant github teams.

      The plan for the modification is as follows:

      Have a github action that:

      • triggers when the files in lists/** are updated
      • appends the special token from a repository secret called TEAM_SYNC_TOKEN that allows it to read and write group members into GH_TOKEN .
      • reads the files from the repo and extracts the desired list of github logins from these
      • for each login in the desired list not present in the github team do add it to the team
      • for each member in the github team not in the desired list remove it from the team
      • keep vuvova and gkodinov to the github teams no matter what.

      Unfortunately the Members permission that can be granted to a PAT (https://github.com/settings/personal-access-tokens/new) is not granular enough and allows editing of ALL teams the user that has generated it can access. Granting that to all MariaDB organization members might be a risk even if generated by gkodinov.

      Attachments

        Activity

          People

            gkodinov Georgi Kodinov
            gkodinov Georgi Kodinov
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 2d
                2d
                Remaining:
                0d
                Logged:
                Time Not Required
                Not Specified