Skip to content

Add microcks - Governance Review - #2099

Open
krol3 wants to merge 3 commits into
cncf:mainfrom
krol3:microcks-gr
Open

Add microcks - Governance Review#2099
krol3 wants to merge 3 commits into
cncf:mainfrom
krol3:microcks-gr

Conversation

@krol3

@krol3 krol3 commented Mar 19, 2026

Copy link
Copy Markdown
Contributor

The governance review required in the issue#2035
Draft notes here: https://hackmd.io/@krol/SJLahh_9Wg

/closes #2035

@github-actions github-actions Bot added needs-triage Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied) needs-kind Indicates an issue or PR that is missing an issue type or kind (a kind/foo label) labels Apr 22, 2026
@github-actions github-actions Bot added the needs-group Indicates an issue or PR that has not been assigned a group (toc or tag/foo label applied) label Apr 22, 2026
@riaankleinhans riaankleinhans added toc toc specific issue triage/valid Issue or PR is valid with enough information to be actionable kind/review Item related to a governance, tech, or other review and removed needs-group Indicates an issue or PR that has not been assigned a group (toc or tag/foo label applied) needs-triage Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied) needs-kind Indicates an issue or PR that is missing an issue type or kind (a kind/foo label) labels May 4, 2026
@angellk

angellk commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

@krol3 please fix so the governance review isn't under the security reviews folder

Signed-off-by: Carol Valencia <krol3@users.noreply.github.com>
Signed-off-by: carolina valencia <krol3@users.noreply.github.com>
@krol3
krol3 marked this pull request as ready for review June 22, 2026 00:06
@krol3
krol3 requested review from a team as code owners June 22, 2026 00:06
@krol3

krol3 commented Jun 22, 2026

Copy link
Copy Markdown
Contributor Author

@krol3 please fix so the governance review isn't under the security reviews folder

Thank you. It was fixed.

@joshgav joshgav added the review/governance Project Governance Review label Jun 25, 2026
@github-project-automation github-project-automation Bot moved this to New - Pending Review in Project Reviews Jun 25, 2026
@joshgav joshgav added the sub/project-reviews TOC Project Review Subproject label Jun 25, 2026
@joshgav joshgav moved this from New - Pending Review to In Progress in Project Reviews Jun 25, 2026
@krol3 krol3 mentioned this pull request Jul 9, 2026
@joshgav

joshgav commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

@krol3 can you remove the changes within the "security-assessment" folder? Then I think this is ready for merge.
Did you have any additional comments @yada or @angellk?

@yada

yada commented Aug 7, 2026

Copy link
Copy Markdown

@joshgav, all good on our side. We’ll refer back to this review as we address its recommendations. Thank you.

Update — September 7, 2026: Following the approval of the governance review, we are now starting the follow-up work. We’ll add a separate comment to this PR for each suggested improvement once it is completed.

Signed-off-by: Josh Gavant <joshgavant@gmail.com>
@joshgav

joshgav commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

I fixed so the PR doesn't touch the security-assessment folder anymore.
With that I think we are good to merge.
Thank you @krol3!

@brandtkeller brandtkeller left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm - great governance review for Microcks.

* **Ensure `CODE_OF_CONDUCT.md` explicitly references `conduct@cncf.io`** as the escalation path for maintainer-involving reports, so that reporters are clearly directed to the CNCF CoC Committee. The project-level `info@microcks.io` contact may remain for general enquiries.
* **Publish a sub-project inventory.** A single document listing all active repositories in the Microcks organisation, their maturity status, current Code Owner or Maintainer assignments, and lifecycle stage would make the scope of the project legible to external reviewers and prospective contributors.
* **Add a "last reviewed" date to `GOVERNANCE.md`** to allow future reviewers to confirm document currency at a glance.
* **Continue growing independent Maintainers.** With two of three current Maintainers sponsored by Postman, the project should articulate a concrete target (e.g., majority of Maintainers from independent organisations by graduation) and timeline. The Steering Committee's adopter representation is a positive structural complement but does not substitute for independent Maintainer diversity at the binding-vote level.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agree with this and the overlays it has for vendor neutrality - there may need to be provisions for number of votes allowed per organization to obtain the supermajority acceptance.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Organization-balanced voting implemented

Thanks @brandtkeller for the recommendation. Microcks has adopted organization-balanced voting for formal governance decisions, using one vote per affiliation regardless of Maintainer
headcount.

Routine technical decisions remain under lazy consensus and individual Maintainer authority. Formal governance decisions now require a two-thirds majority of all eligible organizational
votes, ensuring that no single organization can control the project’s governance alone.

The change was approved by all three current Maintainers, representing both Postman and AXA France:

Following the merge, GOVERNANCE.md and MAINTAINERS.md were successfully replicated across all Microcks repositories where these organization-wide governance files apply:

https://github.com/microcks/.github/actions/runs/34251534743

@yada

yada commented Sep 7, 2026

Copy link
Copy Markdown

Following the approval of the governance review, we are now starting the follow-up work. We’ll add a separate comment to this PR for each suggested improvement once it is completed.

@yada

yada commented Sep 8, 2026

Copy link
Copy Markdown

Secure vulnerability reporting

Addressed in Microcks .github PR #94.

The updated security policy now requires private reporting through security@microcks.io, establishes acknowledgement within five business days, defines a 90-day coordinated-disclosure
target, and clarifies remediation and Security Team responsibilities.

Final policy: https://github.com/microcks/.github/blob/main/SECURITY.md
Replication: https://github.com/microcks/.github/actions/runs/34286520276

The policy was successfully replicated to the Microcks repositories where it is needed and relevant.

@yada

yada commented Sep 11, 2026

Copy link
Copy Markdown

✅ Completed the Code of Conduct escalation update in microcks/.github#95.

The Maintainer vote passed, the PR was merged, and the updated CODE_OF_CONDUCT.md and GOVERNANCE.md files were successfully replicated to Microcks repositories where needed and relevant:
https://github.com/microcks/.github/actions/runs/34543115542

@yada

yada commented Sep 11, 2026

Copy link
Copy Markdown

Project and repository inventory

Completed in microcks/.github#96.

The organization-balanced Maintainer vote passed, and the PR was merged. SUBPROJECTS.md now provides the canonical inventory of Microcks repositories, including their scope, lifecycle, ownership, and CLOMonitor coverage.

Canonical inventory: https://github.com/microcks/.github/blob/main/SUBPROJECTS.md
Governance reference: https://github.com/microcks/.github/blob/main/GOVERNANCE.md
Successful replication: https://github.com/microcks/.github/actions/runs/34591435051

The updated GOVERNANCE.md was successfully replicated to Microcks repositories where needed and relevant. SUBPROJECTS.md remains centralized in the .github repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/review Item related to a governance, tech, or other review review/governance Project Governance Review sub/project-reviews TOC Project Review Subproject toc toc specific issue triage/valid Issue or PR is valid with enough information to be actionable

Projects

Status: New
Status: In Progress
Status: No status
Status: No status
Status: No status

Development

Successfully merging this pull request may close these issues.

[Gov. Review]: Microcks

7 participants