Add microcks - Governance Review - #2099
Conversation
|
@krol3 please fix so the governance review isn't under the security reviews folder |
Signed-off-by: Carol Valencia <krol3@users.noreply.github.com>
Signed-off-by: carolina valencia <krol3@users.noreply.github.com>
Thank you. It was fixed. |
|
@joshgav, all good on our side. We’ll refer back to this review as we address its recommendations. Thank you. Update — September 7, 2026: Following the approval of the governance review, we are now starting the follow-up work. We’ll add a separate comment to this PR for each suggested improvement once it is completed. |
Signed-off-by: Josh Gavant <joshgavant@gmail.com>
|
I fixed so the PR doesn't touch the |
brandtkeller
left a comment
There was a problem hiding this comment.
lgtm - great governance review for Microcks.
| * **Ensure `CODE_OF_CONDUCT.md` explicitly references `conduct@cncf.io`** as the escalation path for maintainer-involving reports, so that reporters are clearly directed to the CNCF CoC Committee. The project-level `info@microcks.io` contact may remain for general enquiries. | ||
| * **Publish a sub-project inventory.** A single document listing all active repositories in the Microcks organisation, their maturity status, current Code Owner or Maintainer assignments, and lifecycle stage would make the scope of the project legible to external reviewers and prospective contributors. | ||
| * **Add a "last reviewed" date to `GOVERNANCE.md`** to allow future reviewers to confirm document currency at a glance. | ||
| * **Continue growing independent Maintainers.** With two of three current Maintainers sponsored by Postman, the project should articulate a concrete target (e.g., majority of Maintainers from independent organisations by graduation) and timeline. The Steering Committee's adopter representation is a positive structural complement but does not substitute for independent Maintainer diversity at the binding-vote level. |
There was a problem hiding this comment.
Agree with this and the overlays it has for vendor neutrality - there may need to be provisions for number of votes allowed per organization to obtain the supermajority acceptance.
There was a problem hiding this comment.
✅ Organization-balanced voting implemented
Thanks @brandtkeller for the recommendation. Microcks has adopted organization-balanced voting for formal governance decisions, using one vote per affiliation regardless of Maintainer
headcount.
Routine technical decisions remain under lazy consensus and individual Maintainer authority. Formal governance decisions now require a two-thirds majority of all eligible organizational
votes, ensuring that no single organization can control the project’s governance alone.
The change was approved by all three current Maintainers, representing both Postman and AXA France:
- Vote result: 3 of 3 Maintainers — 100% approval
- Implementation: docs: adopt organization-balanced governance voting microcks/.github#93
- Merge commit: microcks/.github@10a7fda
- Governance policy: https://github.com/microcks/.github/blob/main/GOVERNANCE.md#decision-making-and-voting
- Maintainer affiliations: https://github.com/microcks/.github/blob/main/MAINTAINERS.md
Following the merge, GOVERNANCE.md and MAINTAINERS.md were successfully replicated across all Microcks repositories where these organization-wide governance files apply:
https://github.com/microcks/.github/actions/runs/34251534743
|
Following the approval of the governance review, we are now starting the follow-up work. We’ll add a separate comment to this PR for each suggested improvement once it is completed. |
|
✅ Secure vulnerability reporting Addressed in Microcks The updated security policy now requires private reporting through Final policy: https://github.com/microcks/.github/blob/main/SECURITY.md The policy was successfully replicated to the Microcks repositories where it is needed and relevant. |
|
✅ Completed the Code of Conduct escalation update in microcks/.github#95. The Maintainer vote passed, the PR was merged, and the updated |
|
✅ Project and repository inventory Completed in microcks/.github#96. The organization-balanced Maintainer vote passed, and the PR was merged. Canonical inventory: https://github.com/microcks/.github/blob/main/SUBPROJECTS.md The updated |
The governance review required in the issue#2035
Draft notes here: https://hackmd.io/@krol/SJLahh_9Wg
/closes #2035