Request 'sethmlarson' be added as repo admin #1363
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This is a request to add myself as a repository admin to the python/cpython repository to be able to evaluate GitHub Security Advisories (GHSA) for a Python Security Response Team ticketing system.
GHSA is a strange feature, where only admins have the ability to "accept" reports and close tickets, even when other users and teams are added as "Collaborators" to a specific ticket (from what I can see, collaborators only have the ability to edit an advisory but not)
I wanted to add bedevere-like commands to the PSRT GitHub bot that collaborators could type in comments in order to change the state of GHSAs, but there is no API to retrieve the comments of an advisory. This means that for now if we're going to migrate to GHSA we need an admin clicking a button sometimes. This might be okay, since it's not a departure from what PSRT admins deal with today with the PSRT mailing list (needing to accept a report before it's sent to the wider team).
📚 Documentation preview 📚: https://cpython-devguide--1363.org.readthedocs.build/