Skip to content

Update PSRT inactivity policy - #1911

Open
StanFromIreland wants to merge 1 commit into
python:mainfrom
StanFromIreland:security/inactivity-policy
Open

StanFromIreland wants to merge 1 commit into
python:mainfrom
StanFromIreland:security/inactivity-policy

Conversation

@StanFromIreland

Copy link
Copy Markdown
Member

Changes based on the recent PSRT decisions that:

  • Member activity is reviewed biannually.
  • Former RMs and PSRT admins are included in the inactivity check.

CC @ambv please note that I've removed your RM manager note, in concordance with python/peps@03bdeb3.

@read-the-docs-community

Copy link
Copy Markdown

Documentation build overview

📚 CPython devguide | 🛠️ Build #34679086 | 📁 Comparing 49398ad against latest (781e8d8)

  🔍 Preview build  

1 file changed
± security/psrt/index.html

Comment thread security/psrt.rst

Members of the PSRT who are a Release Manager or Steering Council member may
remain in the PSRT regardless of inactivity in vulnerability reports.
When a Release Manager's term ends, their PSRT membership becomes a regular

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we need to define the end of an RM's term, or is it obvious? I'd define it as after the official EOL of the last release they are an RM for.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's obvious, but we can be explicit.

That definition makes sense: they no longer need to make any security releases for their versions, so there's no need for them to be present unless they want to be active.


Aside: The "may" in "Members of the PSRT who are a Release Manager or Steering Council member may remain in the PSRT regardless of inactivity in vulnerability reports" suggests membership is optional for RMs (and SC). I was told I had to join, and membership is now required by PEP 101.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd define it as after the official EOL of the last release they are an RM for.

This however, is technically not what we've been doing. We list Steve and Ned as RMs, however as per PEP 101 they're the {W,M}Es. To continue this practice, I suggest something like "as specified in PEP 101" since we're including the slightly broader release team?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, RM members should be mandatory, and optional for SC members. I'd list release experts (WE, ME) as optional but allowed even if they aren't active. But yeah, we can cross reference PEP 101 if you think that's better.

@warsaw warsaw left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Other than one question, LGTM!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants