Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [jakartaee-tck-dev] Fwd: [ee4j-pmc] Removal of bots from our Github Organization

Hi Scott,

Just to add to the below, the eclipse-jakartaee-tck-bot which is used in https://ci.eclipse.org/jakartaee-tck/ will no longer have write permissions on the repos which have come up in the audit list.

It is suggested that this will have no impact on the CI jobs as we are using the eclipse-jakartaee-tck-bot user only for cloning/reading the repo.

Bug https://bugs.eclipse.org/bugs/show_bug.cgi?id=560123 is updated with this discussion, and the above scenario is being tested as of now.

Regards,
Alwin

On 18/02/20 5:21 PM, Jan Supol wrote:
Hi,

This is the answer I got from our engineering team:

> All bots which have names like [projectname]robot are actually legacy robots which existed for related projects before those projects where transferred to Eclipse Foundation. > Thus those *robots have write (furthermore administrator) permissions to related projects. Since projects where migrated, access rights where migrated as well. > But Eclipse Foundation established new robots for newly migrated projects. They are named [projectname]-bot and those bots belong to the Eclipse Foundation. And those and only > those bots are used for releases, jobs runs, technical pull requests etc. There is no harm in removing legacy robots as they shall not be used anymore.

Thanks,

Jan

On 17.02.2020 16:48, Scott Marlow wrote:
Hi TCK dev list,

Does anyone know what the below means, in terms of changes that we
actually need to make for all of the referenced TCK projects? Any
volunteers to look into this and be the TCK robot expert?  If you know
how to address this but don't have time, perhaps responding here or
via a new TCK issue, with the changes needed to address, that could be
done by someone else, would help ensure our TCK testing doesn't stop
working on March 3rd.

Scott

---------- Forwarded message ---------
From: Christopher Guindon <chris.guindon@xxxxxxxxxxxxxxxxxxxxxx>
Date: Fri, Feb 14, 2020 at 1:47 PM
Subject: [ee4j-pmc] Removal of bots from our Github Organization
To: <ee4j-pmc@xxxxxxxxxxx>, <ee4j-build@xxxxxxxxxxx>


Dear Committers,


We recently did an audit of our various Github organizations and we
found a few bot accounts with write access to some repositories
managed by the Eclipse Foundation.


We have a strict policy about who can get write access to Eclipse
projects. See https://urldefense.com/v3/__https://wiki.eclipse.org/CBI*GitHub_and_Bot_Accounts__;Iw!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV6hmr8HW$ for
details about said policy.


For various reasons (details inline), the following bots do not fit
into this scheme. Therefore we plan on removing them on 2020/03/03
from the repositories listed below.


https://urldefense.com/v3/__https://github.com/glassfishrobot__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV3daODXB$ (account) This account is not owned
by the Eclipse Foundation

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/common-annotations-api__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV0Xn7cNE$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/concurrency-api__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyVzdavI54$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/concurrency-ri__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyVwgaL7oE$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/security-examples__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV1Ajc8aI$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/security-api__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV5CqVmhB$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/jaxrs-api__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyVwNwtwe6$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/jms-api__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV-v1YNQT$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/genericjmsra__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV8qlDWI9$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/jsonp__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV8xt1VSa$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/jta-api__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV9yctH0S$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/openmq__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV1wIlkD2$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/tyrus__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV4jZ9vCN$

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/websocket-api__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyVxFI7NE5$

https://urldefense.com/v3/__https://github.com/jerseyrobot__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV8OeYbeq$ (account) This account is not owned by
the Eclipse Foundation

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/jersey__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV1F9vq8q$

https://urldefense.com/v3/__https://github.com/jsonbrobot__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV0BGxxMB$ (account) This account is not owned by
the Eclipse Foundation

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/jsonb-api__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyVxkFL3bg$

https://urldefense.com/v3/__https://github.com/eclipse-jakartaee-tck-bot__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV1dui0OK$ (account)

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/bvtck-porting__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyVzWw-cxL$
(eclipse-jakartaee-tck-bot is associated with project
ee4j.jarkartaee-tck while repo eclipse-ee4j/bvtck-porting is
associated with project ee4j.bean-validation)

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/ditck-porting__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV5_0Oul0$
(eclipse-jakartaee-tck-bot is associated with project
ee4j.jarkartaee-tck while repo eclipse-ee4j/ditck-porting is
associated with project ee4j.glassfish)

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/cditck-porting__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV6py04xY$
(eclipse-jakartaee-tck-bot is associated with project
ee4j.jarkartaee-tck while repo eclipse-ee4j/cditck-porting is
associated with project ee4j.cdi)

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/jaf-tck__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyVwcb12e1$ (eclipse-jakartaee-tck-bot is
associated with project ee4j.jarkartaee-tck while repo
eclipse-ee4j/jaf-tck is associated with project ee4j.jaf)

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/jaxb-tck__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyVwhAf1BP$ (eclipse-jakartaee-tck-bot is
associated with project ee4j.jarkartaee-tck while repo
eclipse-ee4j/jaxb-tck is associated with project ee4j.jaxb)

https://urldefense.com/v3/__https://github.com/eclipse-ee4j/mail-tck__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyVz_NuHqT$ (eclipse-jakartaee-tck-bot is
associated with project ee4j.jarkartaee-tck while repo
eclipse-ee4j/mail-tck is associated with project ee4j.mail)


Please reach out to us by replying to Bug
https://urldefense.com/v3/__https://bugs.eclipse.org/bugs/show_bug.cgi?id=560123__;!!GqivPVa7Brio!MhRIhVdHTKXv7u-HMOLO8fBEwQSvYm7-5DudE6BsFrKxXa5hFwkUVcTyV-5MU_8p$ by February 27 if
you have concerns and if you would like some assistance to workaround
the induced limitations. Cheers,

_______________________________________________
jakartaee-tck-dev mailing list
jakartaee-tck-dev@xxxxxxxxxxx
To change your delivery options, retrieve your password, or unsubscribe from this list, visit https://urldefense.com/v3/__https://www.eclipse.org/mailman/listinfo/jakartaee-tck-dev__;!!GqivPVa7Brio!PMzwQj0d6Zozb5jSQL_LcJF6MsEASNGh0UCbOBAeS9rLyC809Vvd55j3UP03xFtSPA$




Back to the top