[ 
https://issues.apache.org/jira/browse/SLING-7245?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16885254#comment-16885254
 ] 

Bertrand Delacretaz commented on SLING-7245:
--------------------------------------------

My understanding of INFRA-18748 is that builds from non-committers should not 
happen to avoid denial of service attacks.

IIRC for [https://cwiki.apache.org/] people have to ask the PMC to get write 
access - a similar mechanism would sound reasonable for PR builds: authorize 
them if the GitHub username is included in a list that the PMC manages.

I have mentioned this suggestion in the infra thread mentioned above.

> Validate pull requests using Jenkins
> ------------------------------------
>
>                 Key: SLING-7245
>                 URL: https://issues.apache.org/jira/browse/SLING-7245
>             Project: Sling
>          Issue Type: Improvement
>          Components: Build and Source Control
>            Reporter: Robert Munteanu
>            Assignee: Robert Munteanu
>            Priority: Major
>         Attachments: image-2019-01-30-12-52-54-106.png, 
> image-2019-01-30-12-52-56-248.png
>
>          Time Spent: 40m
>  Remaining Estimate: 0h
>
> We should refine the work done in SLING-7163 and validate PRs using Jenkins.



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)

Reply via email to