| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
There was a problem hiding this comment.
LGTM
Sorry, something went wrong.
There was a problem hiding this comment.
typo, here and in the commit message: mamy
Sorry, something went wrong.
There was a problem hiding this comment.
Perhaps "strongly suggest". I'd even prefer "wait until they've enabled" but this is probably a discussion that lives someplace else.
Sorry, something went wrong.
There was a problem hiding this comment.
@jbergstroem Let's keep it as «suggest» for now and re-evaluate later, there could be some issues with enabling 2FA that we are not aware of, and we don't want to scare new people from being added as collaborators.
Once we collect some feedback/results on this process, we could make it stricter, either by «strongly suggest» or by even enforcing 2FA as a hard requirement.
Sorry, something went wrong.
There was a problem hiding this comment.
Isn't this a very lengthy line?
Sorry, something went wrong.
There was a problem hiding this comment.
@thefourtheye It's wrapped now. Thanks.
Sorry, something went wrong.
There was a problem hiding this comment.
@addaleax typo fixed, thanks!
Sorry, something went wrong.
There was a problem hiding this comment.
LGTM with typo fixed
Sorry, something went wrong.
There was a problem hiding this comment.
LGTM with a typo fix.
Sorry, something went wrong.
There was a problem hiding this comment.
LGTM with fix and postponing the 2fa talk.
Sorry, something went wrong.
|
Btw, /cc @nodejs/collaborators. |
Sorry, something went wrong.
There was a problem hiding this comment.
LGTM. However I experienced major disruptions in my dev workflows when I activated this. Obviously there are privileges, but imo git is resilient enough and collaborators usually don't have to many org rights in the beginning, no?
Sorry, something went wrong.
|
@eljefedelrodeodeljefe I'm curious, what kind of disruptions have you encountered? There are many ways to do 2fa, you don't even have to have a (smart)phone. |
Sorry, something went wrong.
|
@mscdex nothing too blocking, but annoyances like: needing to re-authenticate everywhere, this sometimes not working properly, re-auth in multiple terminals, git clients on the same machine, Not being able to quickly pull / clone on remote machines, where you don't store config, especially in non-OSS environments, sometimes auth on remote not even working, the list goes on. |
Sorry, something went wrong.
|
@eljefedelrodeodeljefe Is that with https? I've never had any problems with ssh. |
Sorry, something went wrong.
In the onboarding document, add a note to ask the new Collaborator if they are using two-factor authentication on their GitHub account. If they are not, suggest that they enable it as their account will have elevated privileges in many of the Node.js repositories.
|
LGTM |
Sorry, something went wrong.
|
ugh sausage fingers... sorry |
Sorry, something went wrong.
There was a problem hiding this comment.
LGTM
Sorry, something went wrong.
In the onboarding document, add a note to ask the new Collaborator if they are using two-factor authentication on their GitHub account. If they are not, suggest that they enable it as their account will have elevated privileges in many of the Node.js repositories. PR-URL: nodejs#8776 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Ilkka Myller <ilkka.myller@nodefield.com> Reviewed-By: Сковорода Никита Андреевич <chalkerx@gmail.com> Reviewed-By: Johan Bergstrom <bugs@bergstroem.nu> Reviewed-By: Robert Jefe Lindstaedt <robert.lindstaedt@gmail.com> Reviewed-By: Myles Borins <myles.borins@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com>
In the onboarding document, add a note to ask the new Collaborator if they are using two-factor authentication on their GitHub account. If they are not, suggest that they enable it as their account will have elevated privileges in many of the Node.js repositories. PR-URL: #8776 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Ilkka Myller <ilkka.myller@nodefield.com> Reviewed-By: Сковорода Никита Андреевич <chalkerx@gmail.com> Reviewed-By: Johan Bergstrom <bugs@bergstroem.nu> Reviewed-By: Robert Jefe Lindstaedt <robert.lindstaedt@gmail.com> Reviewed-By: Myles Borins <myles.borins@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com>
|
I'm curious, what are the extra privileges? |
Sorry, something went wrong.
In the onboarding document, add a note to ask the new Collaborator if they are using two-factor authentication on their GitHub account. If they are not, suggest that they enable it as their account will have elevated privileges in many of the Node.js repositories. PR-URL: #8776 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Ilkka Myller <ilkka.myller@nodefield.com> Reviewed-By: Сковорода Никита Андреевич <chalkerx@gmail.com> Reviewed-By: Johan Bergstrom <bugs@bergstroem.nu> Reviewed-By: Robert Jefe Lindstaedt <robert.lindstaedt@gmail.com> Reviewed-By: Myles Borins <myles.borins@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com>
|
@AndreasMadsen I believe pushing to master, for example |
Sorry, something went wrong.
|
@thealphanerd I could do that before enabling 2FA. |
Sorry, something went wrong.
We encourage 2FA. That is all (at this time). There is currently no connection between "enable 2FA" and "get more privileges" for the typical Collaborator. |
Sorry, something went wrong.
|
2FA is required if you're on the security team, and possibly the build team as well. Do we also have requirements for PGP signing for both of those groups as well? Is this written down anywhere? |
Sorry, something went wrong.
Signing what exactly? |
Sorry, something went wrong.
In the onboarding document, add a note to ask the new Collaborator if they are using two-factor authentication on their GitHub account. If they are not, suggest that they enable it as their account will have elevated privileges in many of the Node.js repositories. PR-URL: #8776 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Ilkka Myller <ilkka.myller@nodefield.com> Reviewed-By: Сковорода Никита Андреевич <chalkerx@gmail.com> Reviewed-By: Johan Bergstrom <bugs@bergstroem.nu> Reviewed-By: Robert Jefe Lindstaedt <robert.lindstaedt@gmail.com> Reviewed-By: Myles Borins <myles.borins@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com>
In the onboarding document, add a note to ask the new Collaborator if they are using two-factor authentication on their GitHub account. If they are not, suggest that they enable it as their account will have elevated privileges in many of the Node.js repositories. PR-URL: #8776 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Ilkka Myller <ilkka.myller@nodefield.com> Reviewed-By: Сковорода Никита Андреевич <chalkerx@gmail.com> Reviewed-By: Johan Bergstrom <bugs@bergstroem.nu> Reviewed-By: Robert Jefe Lindstaedt <robert.lindstaedt@gmail.com> Reviewed-By: Myles Borins <myles.borins@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com>
In the onboarding document, add a note to ask the new Collaborator if they are using two-factor authentication on their GitHub account. If they are not, suggest that they enable it as their account will have elevated privileges in many of the Node.js repositories. PR-URL: #8776 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Ilkka Myller <ilkka.myller@nodefield.com> Reviewed-By: Сковорода Никита Андреевич <chalkerx@gmail.com> Reviewed-By: Johan Bergstrom <bugs@bergstroem.nu> Reviewed-By: Robert Jefe Lindstaedt <robert.lindstaedt@gmail.com> Reviewed-By: Myles Borins <myles.borins@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com>
In the onboarding document, add a note to ask the new Collaborator if they are using two-factor authentication on their GitHub account. If they are not, suggest that they enable it as their account will have elevated privileges in many of the Node.js repositories. PR-URL: #8776 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Ilkka Myller <ilkka.myller@nodefield.com> Reviewed-By: Сковорода Никита Андреевич <chalkerx@gmail.com> Reviewed-By: Johan Bergstrom <bugs@bergstroem.nu> Reviewed-By: Robert Jefe Lindstaedt <robert.lindstaedt@gmail.com> Reviewed-By: Myles Borins <myles.borins@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com>
| Back | FazBrowse Home | New Git URL |
Checklist
Affected core subsystem(s)
doc
Description of change
In the onboarding document, add a note to ask the new Collaborator if
they are using two-factor authentication on their GitHub account. If
they are not, suggest that they enable it as their account will have
elevated privileges in mamy of the Node.js repositories.