Remove the CI-whitelsit GitHub mirror
Description
Activity

Eyal Edri February 26, 2017 at 4:14 PM
ovirt-site is a Github project, not Gerrit, so the comparison isn't relevant.
jenkins-whitelist is an infra project and as all infra repos, managed in Gerrit.
The same reason we won't accept engine or vdsm patches from GitHub because they are managed in Gerrit, we can't accept it for this project.
It happens that 99% percent of patches or requests are done via Gerrit currently, So I don't see a strong reason to move the jenkins-whitelist to GitHub.
New projects like 'ovirt-web-ui' that existing only in GitHub are already supported, so you can't say we don't support PRs from GitHub.
As for making it private repo on Gerrit, we can consider it, though unless you can spoof yourself into Gerrit with fake email, not sure if its needed.

Nir Soffer February 26, 2017 at 3:57 PM
On Sun, Feb 26, 2017 at 5:47 PM, Barak Korren (oVirt JIRA) <
Any ovirt patch on github contains the email address of the author.
There is no privacy, and there should be no privacy on free software
project.
This change is not needed and very wrong; we should make it easy to add
someone to the whitelist.
The correct change would be to accept pull requests on github, like
ovirt-site.
Nir

Barak Korren February 26, 2017 at 3:47 PM
we should probably make it private too, like the infra-hiera repo

Eyal Edri February 26, 2017 at 3:39 PM
Well. the gerrit repo jenkins-whitelist is also public no?
On Sun, Feb 26, 2017 at 5:27 PM, Barak Korren (oVirt JIRA) <
–
Eyal Edri
Associate Manager
RHV DevOps
EMEA ENG Virtualization R&D
Red Hat Israel
phone: +972-9-7692018
irc: eedri (on #tlv #rhev-dev #rhev-integ)

Barak Korren February 26, 2017 at 3:27 PM
Because the whitelist itslef and peoples email addresses is sensitive information

Eyal Edri February 26, 2017 at 3:23 PM
How so?
AFAIK the github repo is readonly and can't accept PR's.

Barak Korren February 26, 2017 at 3:18 PM
Well, this can be considered a security issue...

Eyal Edri February 26, 2017 at 3:14 PM
No, just time & priorities.
I don't think it deserve high priority when looking at other tasks open
On Sun, Feb 26, 2017 at 4:39 PM, Barak Korren (oVirt JIRA) <
–
Eyal Edri
Associate Manager
RHV DevOps
EMEA ENG Virtualization R&D
Red Hat Israel
phone: +972-9-7692018
irc: eedri (on #tlv #rhev-dev #rhev-integ)

Barak Korren February 26, 2017 at 2:39 PM
Is there any reason NOT to do this?
Details
Assignee
Former userFormer user(Deactivated)Reporter
Barak KorrenBarak Korren(Deactivated)Blocked By
need to improve whitelist and decide on next actionsComponents
Priority
Medium
Details
Details
Assignee

Reporter

Having this on GitHub makes the a list of people's email-addresses far too public.
It also makes people confused and try to update it with GitHub pull requests.
We should probably remove the GitHub mirror, and also make sure the Gerrit repo is also not that easy to look into.