Skip to content

Add microcks - Governance Review - #2099

Open
krol3 wants to merge 3 commits into
cncf:mainfrom
krol3:microcks-gr
Open

krol3 wants to merge 3 commits into
cncf:mainfrom
krol3:microcks-gr

Conversation

@krol3

@krol3 krol3 commented Mar 19, 2026

Copy link
Copy Markdown
Contributor

The governance review required in the issue#2035
Draft notes here: https://hackmd.io/@krol/SJLahh_9Wg

/closes #2035

@github-actions github-actions Bot added needs-triage Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied) needs-kind Indicates an issue or PR that is missing an issue type or kind (a kind/foo label) labels Apr 22, 2026
@github-actions github-actions Bot added the needs-group Indicates an issue or PR that has not been assigned a group (toc or tag/foo label applied) label Apr 22, 2026
@riaankleinhans riaankleinhans added toc toc specific issue triage/valid Issue or PR is valid with enough information to be actionable kind/review Item related to a governance, tech, or other review and removed needs-group Indicates an issue or PR that has not been assigned a group (toc or tag/foo label applied) needs-triage Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied) needs-kind Indicates an issue or PR that is missing an issue type or kind (a kind/foo label) labels May 4, 2026
@angellk

angellk commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

@krol3 please fix so the governance review isn't under the security reviews folder

Signed-off-by: Carol Valencia <krol3@users.noreply.github.com>
Signed-off-by: carolina valencia <krol3@users.noreply.github.com>
@krol3
krol3 marked this pull request as ready for review June 22, 2026 00:06
@krol3
krol3 requested review from a team as code owners June 22, 2026 00:06
@krol3

krol3 commented Jun 22, 2026

Copy link
Copy Markdown
Contributor Author

@krol3 please fix so the governance review isn't under the security reviews folder

Thank you. It was fixed.

@joshgav joshgav added the review/governance Project Governance Review label Jun 25, 2026
@github-project-automation github-project-automation Bot moved this to New - Pending Review in Project Reviews Jun 25, 2026
@joshgav joshgav added the sub/project-reviews TOC Project Review Subproject label Jun 25, 2026
@joshgav joshgav moved this from New - Pending Review to In Progress in Project Reviews Jun 25, 2026
@krol3 krol3 mentioned this pull request Jul 9, 2026
@joshgav

joshgav commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

@krol3 can you remove the changes within the "security-assessment" folder? Then I think this is ready for merge.
Did you have any additional comments @yada or @angellk?

@yada

yada commented Aug 7, 2026

Copy link
Copy Markdown

@joshgav, all good on our side. We’ll refer back to this review as we address its recommendations. Thank you.

Update — September 7, 2026: Following the approval of the governance review, we are now starting the follow-up work. We’ll add a separate comment to this PR for each suggested improvement once it is completed.

Signed-off-by: Josh Gavant <joshgavant@gmail.com>
@joshgav

joshgav commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

I fixed so the PR doesn't touch the security-assessment folder anymore.
With that I think we are good to merge.
Thank you @krol3!

@brandtkeller brandtkeller left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm - great governance review for Microcks.

* **Ensure `CODE_OF_CONDUCT.md` explicitly references `conduct@cncf.io`** as the escalation path for maintainer-involving reports, so that reporters are clearly directed to the CNCF CoC Committee. The project-level `info@microcks.io` contact may remain for general enquiries.
* **Publish a sub-project inventory.** A single document listing all active repositories in the Microcks organisation, their maturity status, current Code Owner or Maintainer assignments, and lifecycle stage would make the scope of the project legible to external reviewers and prospective contributors.
* **Add a "last reviewed" date to `GOVERNANCE.md`** to allow future reviewers to confirm document currency at a glance.
* **Continue growing independent Maintainers.** With two of three current Maintainers sponsored by Postman, the project should articulate a concrete target (e.g., majority of Maintainers from independent organisations by graduation) and timeline. The Steering Committee's adopter representation is a positive structural complement but does not substitute for independent Maintainer diversity at the binding-vote level.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agree with this and the overlays it has for vendor neutrality - there may need to be provisions for number of votes allowed per organization to obtain the supermajority acceptance.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Organization-balanced voting implemented

Thanks @brandtkeller for the recommendation. Microcks has adopted organization-balanced voting for formal governance decisions, using one vote per affiliation regardless of Maintainer
headcount.

Routine technical decisions remain under lazy consensus and individual Maintainer authority. Formal governance decisions now require a two-thirds majority of all eligible organizational
votes, ensuring that no single organization can control the project’s governance alone.

The change was approved by all three current Maintainers, representing both Postman and AXA France:

Following the merge, GOVERNANCE.md and MAINTAINERS.md were successfully replicated across all Microcks repositories where these organization-wide governance files apply:

https://github.com/microcks/.github/actions/runs/34251534743

@yada

yada commented Sep 7, 2026

Copy link
Copy Markdown

Following the approval of the governance review, we are now starting the follow-up work. We’ll add a separate comment to this PR for each suggested improvement once it is completed.

@yada

yada commented Sep 8, 2026

Copy link
Copy Markdown

Secure vulnerability reporting

Addressed in Microcks .github PR #94.

The updated security policy now requires private reporting through security@microcks.io, establishes acknowledgement within five business days, defines a 90-day coordinated-disclosure
target, and clarifies remediation and Security Team responsibilities.

Final policy: https://github.com/microcks/.github/blob/main/SECURITY.md
Replication: https://github.com/microcks/.github/actions/runs/34286520276

The policy was successfully replicated to the Microcks repositories where it is needed and relevant.

@yada

yada commented Sep 11, 2026

Copy link
Copy Markdown

✅ Completed the Code of Conduct escalation update in microcks/.github#95.

The Maintainer vote passed, the PR was merged, and the updated CODE_OF_CONDUCT.md and GOVERNANCE.md files were successfully replicated to Microcks repositories where needed and relevant:
https://github.com/microcks/.github/actions/runs/34543115542

@yada

yada commented Sep 11, 2026

Copy link
Copy Markdown

Project and repository inventory

Completed in microcks/.github#96.

The organization-balanced Maintainer vote passed, and the PR was merged. SUBPROJECTS.md now provides the canonical inventory of Microcks repositories, including their scope, lifecycle, ownership, and CLOMonitor coverage.

Canonical inventory: https://github.com/microcks/.github/blob/main/SUBPROJECTS.md
Governance reference: https://github.com/microcks/.github/blob/main/GOVERNANCE.md
Successful replication: https://github.com/microcks/.github/actions/runs/34591435051

The updated GOVERNANCE.md was successfully replicated to Microcks repositories where needed and relevant. SUBPROJECTS.md remains centralized in the .github repository.

@yada

yada commented Sep 14, 2026

Copy link
Copy Markdown

Objective contributor ladder and governance review cadence

Completed in microcks/.github#98.

The governance policy now defines measurable eligibility criteria for Maintainers and Code Owners, requires promotion nominations to include public supporting evidence, and recognizes equivalent asynchronous community participation.

GOVERNANCE.md also includes a last-reviewed date and requires a public governance review at least once every twelve months.

The organization-balanced Maintainer vote passed, the PR was merged, and the updated governance file was successfully replicated to Microcks repositories where needed and relevant.

Final policy: https://github.com/microcks/.github/blob/main/GOVERNANCE.md
Replication: https://github.com/microcks/.github/actions/runs/34856733045

@yada

yada commented Sep 14, 2026

Copy link
Copy Markdown

Community meeting documentation and recordings

Completed through microcks/community#142 and commit microcks/community@21d2601.

The community documentation now provides consistent meeting schedules and direct links to the publicly available recordings:

Significant decisions and follow-up actions are recorded through durable public GitHub issues, pull requests, and discussions. Written minutes are not currently published for every meeting, but recordings remain publicly accessible.

Meeting documentation: https://github.com/microcks/community/blob/main/JOIN-OUR-MEETINGS.md

@yada

yada commented Sep 14, 2026

Copy link
Copy Markdown

🔄 Maintainer diversity — ongoing

We acknowledge the governance review’s observation that two of the three current Microcks Maintainers are sponsored by Postman. This recommendation remains open and requires continued community and Maintainer development rather than a documentation-only change.

As immediate governance safeguards, Microcks has adopted organization-balanced voting and objective, publicly verifiable promotion criteria:

These measures prevent a single organization from controlling formal decisions through Maintainer headcount and provide a transparent path for contributors from additional organizations to become Code Owners and Maintainers.

We will continue developing and promoting independent Maintainers, with the objective that no single organization holds a majority of Maintainer seats before Microcks applies for CNCF Graduation.

@yada

yada commented Sep 14, 2026

Copy link
Copy Markdown

@joshgav @brandtkeller @krol3, the Microcks follow-up is now complete for all actionable governance and documentation recommendations.

The individual updates above cover secure vulnerability reporting, Code of Conduct escalation, the consolidated project inventory, objective contributor-ladder criteria, governance review cadence, and community meeting documentation.

Maintainer diversity is explicitly acknowledged as an ongoing objective, with a target of removing single-organization majority representation before applying for CNCF Graduation.

Could you please provide the final validation and merge this governance review?

One older Auto Label Issues and PRs check remains failed because its pull_request_target workflow refused to check out code from the fork. DCO passes, and the PR is otherwise mergeable. Please let us know if a repository Maintainer needs to rerun or override that check.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/review Item related to a governance, tech, or other review review/governance Project Governance Review sub/project-reviews TOC Project Review Subproject toc toc specific issue triage/valid Issue or PR is valid with enough information to be actionable

Projects

Status: New
Status: In Progress
Status: No status
Status: No status
Status: No status

Development

Successfully merging this pull request may close these issues.

[Gov. Review]: Microcks

7 participants