BTW. I am going to strongly oppose that (ticket is coming)

---------- Forwarded message ---------
From: Jarek Potiuk <ja...@potiuk.com>
Date: Mon, Feb 13, 2023 at 8:55 PM
Subject: Re: [NOTICE] Upcoming global changes to default GitHub
Actions behavior for outside collaborators
To: <us...@infra.apache.org>
Cc: <annou...@infra.apache.org>


I will raise a ticket and explain.

But This would be a huge blow to the Airflow community and almost
immediate burn-out of the active committers if it goes life for
Airflow. And likely many other projects.

I am very strongly convinced it should not be enforced.

J.

On Mon, Feb 13, 2023 at 8:51 PM Daniel Gruno <humbed...@apache.org> wrote:
>
> To Project PMCs:
>
> GitHub for Apache projects is currently set to allow a non-committer
> contributor to use GitHub Actions if a previous pull request by that
> person has been approved.
>
> This has raised some security concerns, and could cause issues with
> overall use and availability of GitHub Actions.
>
> The Infrastructure Team proposes to change the default to “always
> require approval for external contributors”. We intend to make this
> change on Sunday the 19th of March, 2023.
>
> This change will apply to all GitHub repositories that do not already
> have a specific GitHub Actions policy set.
>
> Projects that have a strong desire to use the “only need approval first
> time” option should communicate that, explaining their reasons, in a
> Jira ticket for Infra. Please be as specific as you can in which
> repositories you wish to have this option set for, should you choose to.
>
> With regards,
> Daniel, on behalf of the ASF Infrastructure Team.

Reply via email to