Repository navigation
Remove Inactive Users #1030
Description
Activity
The https://github.com/pkgjs organization contains 28 inactive13 users. That's 70% of the organization4.
In pkgjs we’re going to have an emeritus team, and anyone who is not included in the list in nodejs/package-maintenance#642 will be moved there, unless they are a TSC member or part of the moderation team.
aslo see #1020
Currently, the @nodejs organization contains 69 inactive1 users. That's roughly a fifth of the entire organization2.
Footnotes
1. A user who has not interacted (commenting, committing, etc) on a repository in the organization in the past 12 months. [↩](#user-content-fnref-1-861f13ae9ab3acaf96c3a793855368f5) [↩2](#user-content-fnref-1-2-861f13ae9ab3acaf96c3a793855368f5) 2. As of writing, there are 346 members of the [@nodejs](https://github.com/nodejs) organization. [↩](#user-content-fnref-2-861f13ae9ab3acaf96c3a793855368f5)For the nodejs list:
node-forward-build is owned by the Build WG and is still in use today. Things will break if it is removed from the org.
Some of the identified users are members of the organization for notification purposes.
For example (since these are IBMers who I know are still involved with Node.js):
- @john-yan is a member of platform-aix, platform-ppc and platform-s390. He's in the same IBM team that I am in, although mainly focused on V8 work with @miladfarca.
- @zsw007 is a member of platform-zos.
(FWIW nodejs/node#61308 was opened specifically for the IBM platform teams but the above names were not suggested for removal/clean up.)
Some of the identified users are members of the organization for notification purposes.
Noted. I identified the users with a basic script to fetch members -> check interactions -> log usernames. I know the list likely has false positives.
Inactive users merely being in the org is immaterial - the only thing that matters is if inactive users have permissions that are dangerous to hold, namely, Write or higher on repos (and in some repos, Write might not even matter). Can you filter down to only those users who have such access?
Our most important assets (nodejs/node) has already a script that does this check.
Reacted by Jordan Harband, Beth Griggs, Rafael Gonzaga and Sebastian BeltranInactive users merely being in the org is immaterial - the only thing that matters is if inactive users have permissions that are dangerous to hold, namely, Write or higher on repos (and in some repos, Write might not even matter). Can you filter down to only those users who have such access?
It's not. There are several things that every member of the organization has access to:
- https://github.com/nodejs/moderation (Private Repo; Triage Access)
- https://github.com/nodejs/collaborators-public-votes (Write Access)
- https://github.com/nodejs/nodejs-ambassadors (Private Repo; Read Access)
- Ability to run
pull_requestworkflows without authorization. - Seeing all organization members (although I'm not sure this is a problem)
- The ability to create/transfer repositories in the organization ("organization members have a number of permissions, including the ability to create repositories and projects.")
etc
Then the permissions changes I'd recommend is making mere org membership not automatically grant any permissions. (although 4, 5, and 6 imo aren't really a risk for known actors) 2, for example - only collaborators should have write access.
(Ref: #632)
Currently, the @nodejs organization contains 69 inactive1 users. That's roughly a fifth of the entire organization2.
List
The @pkgjs organization contains 28 inactive13 users. That's 70% of the organization4.
List
Footnotes
A user who has not interacted (commenting, committing, etc) on a repository in the organization in the past 12 months. ↩ ↩2
As of writing, there are 346 members of the @nodejs organization. ↩
Many of the inactive users for @pkgjs are active users in @nodejs ↩
As of writing, there are 40 members of the @pkgjs organization. ↩