Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Charter: Add instructions on how to join CPANSec #20

Open
sjn opened this issue Jul 16, 2023 · 6 comments
Open

Charter: Add instructions on how to join CPANSec #20

sjn opened this issue Jul 16, 2023 · 6 comments
Labels
documentation Improvements or additions to documentation help wanted Extra attention is needed

Comments

@sjn
Copy link
Contributor

sjn commented Jul 16, 2023

How does one join the CPAN Security group?

For now we don't have a formal process, so no vetting or chain of trust.

@sjn sjn converted this from a draft issue Jul 16, 2023
@sjn sjn added the documentation Improvements or additions to documentation label Jul 16, 2023
@sjn sjn added the help wanted Extra attention is needed label Aug 21, 2023
@sjn sjn changed the title Charter: Add instructions on how to join CPAN-SEC Charter: Add instructions on how to join CPANSec Feb 22, 2024
@garu
Copy link
Contributor

garu commented Aug 2, 2024

do we have a draft for this? otherwise I can bring one next meeting and we buiild from there.

@sjn
Copy link
Contributor Author

sjn commented Aug 2, 2024

No draft. We talked about it at a meeting this spring and IIRC, @stigtsp had some opinions on the matter, but it didn't go anywhere. Feel free to put together a draft! :)

I've written an outline of an onboarding text, but since we're not using the forum much, I don't know if instructions like these can fit there, or if they should go in the charter. What do you think?

In any case, we don't really have much of a process at all, so anything you put together would probably be an improvement! :-D

@stigtsp
Copy link
Contributor

stigtsp commented Aug 2, 2024

My thoughts (in TLDR form) on that was:

  • Anyone can join CPANSec and participate in the public forums
  • CPANSec Triage and the cpan-security mailing list is invite only due to pre-release disclosure of vulnerabilities.
  • CPANSec CNA (when/if it gets set up) would be invite only as it requires following CNA rules and procedures, and maybe onboarding trough root-CNA.

@garu
Copy link
Contributor

garu commented Aug 2, 2024

@stigtsp Agreed. Do you also have thoughts on the how? E.g. "I wanna join! What do I do? How do I let people know? At which point in the process will I be able to say that I have joined successfully?"

@sjn
Copy link
Contributor Author

sjn commented Aug 2, 2024

Should we do some vetting? Or require an invitation/recommendation from an existing member? Or some other trust or background verification?

@Tux
Copy link
Contributor

Tux commented Aug 3, 2024

As the Governanbce project was closed, should this issue be closed or assigned to a new project?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation help wanted Extra attention is needed
Development

No branches or pull requests

4 participants