Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add @dlqqq to security team #720

Closed
3 tasks
choldgraf opened this issue May 10, 2024 · 5 comments · Fixed by #721
Closed
3 tasks

Add @dlqqq to security team #720

choldgraf opened this issue May 10, 2024 · 5 comments · Fixed by #721

Comments

@choldgraf
Copy link
Member

We're discussing creating a security team here:

Part of the motivation for this is so that we can add members to the team from other parts of Jupyter, to facilitate security reporting and coordination across the org.

@dlqqq is one-such person, and has requested membership in this team if #716 is created. So this issue is to track answering the question:

Should we add @dlqqq to the security team (if it is created)

We've discussed this a bit via our listserv and there haven't been objections, and we agreed to make the issue first so there was a public record.

Actions

@minrk
Copy link
Member

minrk commented May 10, 2024

Joining the Jupyter Enterprise (#719) may also make this JupyterHub-specific Security team moot, as I think this is one of the things we can do at the Enterprise-level, rather than having to manage it separately for every org. Is that right, @rpwagner?

@minrk
Copy link
Member

minrk commented May 10, 2024

But also for explicitness and expediency, 👍 for me on both creating the team and adding @dlqqq, even if it ends up deprecated in favor of managing the same concept at the Enterprise level.

@choldgraf
Copy link
Member Author

Yeah I think you're right - my feeling is that, given how easy it would be to implement this, we should just do it if there's no controversy in the decision, but if there is controversy in the decision it is not worth extensive debate because this might ask get superceded by the enterprise account anyway

@manics
Copy link
Member

manics commented May 10, 2024

👍 I didn't realise we hadn't actually created the security team yet.

@jasongrout
Copy link

I think this is one of the things we can do at the Enterprise-level, rather than having to manage it separately for every org

I've been poking around in the enterprise settings, and it seems that there are some security enterprise-org level things (like tracking code scanning results, etc.), but it also seems that this specific role of security team is a github org level thing.

So +1 to creating a security team for now, and we'll see what the enterprise org lets us do in the future.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants