Conversation
|
@krol3 please fix so the governance review isn't under the security reviews folder |
Signed-off-by: Carol Valencia <krol3@users.noreply.github.com>
Signed-off-by: carolina valencia <krol3@users.noreply.github.com>
Thank you. It was fixed. |
|
@joshgav, all good on our side. We’ll refer back to this review as we address its recommendations. Thank you. Update — September 7, 2026: Following the approval of the governance review, we are now starting the follow-up work. We’ll add a separate comment to this PR for each suggested improvement once it is completed. |
Signed-off-by: Josh Gavant <joshgavant@gmail.com>
|
I fixed so the PR doesn't touch the |
brandtkeller
left a comment
There was a problem hiding this comment.
lgtm - great governance review for Microcks.
| * **Ensure `CODE_OF_CONDUCT.md` explicitly references `conduct@cncf.io`** as the escalation path for maintainer-involving reports, so that reporters are clearly directed to the CNCF CoC Committee. The project-level `info@microcks.io` contact may remain for general enquiries. | ||
| * **Publish a sub-project inventory.** A single document listing all active repositories in the Microcks organisation, their maturity status, current Code Owner or Maintainer assignments, and lifecycle stage would make the scope of the project legible to external reviewers and prospective contributors. | ||
| * **Add a "last reviewed" date to `GOVERNANCE.md`** to allow future reviewers to confirm document currency at a glance. | ||
| * **Continue growing independent Maintainers.** With two of three current Maintainers sponsored by Postman, the project should articulate a concrete target (e.g., majority of Maintainers from independent organisations by graduation) and timeline. The Steering Committee's adopter representation is a positive structural complement but does not substitute for independent Maintainer diversity at the binding-vote level. |
There was a problem hiding this comment.
Agree with this and the overlays it has for vendor neutrality - there may need to be provisions for number of votes allowed per organization to obtain the supermajority acceptance.
There was a problem hiding this comment.
✅ Organization-balanced voting implemented
Thanks @brandtkeller for the recommendation. Microcks has adopted organization-balanced voting for formal governance decisions, using one vote per affiliation regardless of Maintainer
headcount.
Routine technical decisions remain under lazy consensus and individual Maintainer authority. Formal governance decisions now require a two-thirds majority of all eligible organizational
votes, ensuring that no single organization can control the project’s governance alone.
The change was approved by all three current Maintainers, representing both Postman and AXA France:
- Vote result: 3 of 3 Maintainers — 100% approval
- Implementation: docs: adopt organization-balanced governance voting microcks/.github#93
- Merge commit: microcks/.github@10a7fda
- Governance policy: https://github.com/microcks/.github/blob/main/GOVERNANCE.md#decision-making-and-voting
- Maintainer affiliations: https://github.com/microcks/.github/blob/main/MAINTAINERS.md
Following the merge, GOVERNANCE.md and MAINTAINERS.md were successfully replicated across all Microcks repositories where these organization-wide governance files apply:
https://github.com/microcks/.github/actions/runs/34251534743
|
Following the approval of the governance review, we are now starting the follow-up work. We’ll add a separate comment to this PR for each suggested improvement once it is completed. |
|
✅ Secure vulnerability reporting Addressed in Microcks The updated security policy now requires private reporting through Final policy: https://github.com/microcks/.github/blob/main/SECURITY.md The policy was successfully replicated to the Microcks repositories where it is needed and relevant. |
|
✅ Completed the Code of Conduct escalation update in microcks/.github#95. The Maintainer vote passed, the PR was merged, and the updated |
|
✅ Project and repository inventory Completed in microcks/.github#96. The organization-balanced Maintainer vote passed, and the PR was merged. Canonical inventory: https://github.com/microcks/.github/blob/main/SUBPROJECTS.md The updated |
|
✅ Objective contributor ladder and governance review cadence Completed in microcks/.github#98. The governance policy now defines measurable eligibility criteria for Maintainers and Code Owners, requires promotion nominations to include public supporting evidence, and recognizes equivalent asynchronous community participation.
The organization-balanced Maintainer vote passed, the PR was merged, and the updated governance file was successfully replicated to Microcks repositories where needed and relevant. Final policy: https://github.com/microcks/.github/blob/main/GOVERNANCE.md |
|
✅ Community meeting documentation and recordings Completed through microcks/community#142 and commit microcks/community@21d2601. The community documentation now provides consistent meeting schedules and direct links to the publicly available recordings: Significant decisions and follow-up actions are recorded through durable public GitHub issues, pull requests, and discussions. Written minutes are not currently published for every meeting, but recordings remain publicly accessible. Meeting documentation: https://github.com/microcks/community/blob/main/JOIN-OUR-MEETINGS.md |
|
🔄 Maintainer diversity — ongoing We acknowledge the governance review’s observation that two of the three current Microcks Maintainers are sponsored by Postman. This recommendation remains open and requires continued community and Maintainer development rather than a documentation-only change. As immediate governance safeguards, Microcks has adopted organization-balanced voting and objective, publicly verifiable promotion criteria:
These measures prevent a single organization from controlling formal decisions through Maintainer headcount and provide a transparent path for contributors from additional organizations to become Code Owners and Maintainers. We will continue developing and promoting independent Maintainers, with the objective that no single organization holds a majority of Maintainer seats before Microcks applies for CNCF Graduation. |
|
@joshgav @brandtkeller @krol3, the Microcks follow-up is now complete for all actionable governance and documentation recommendations. The individual updates above cover secure vulnerability reporting, Code of Conduct escalation, the consolidated project inventory, objective contributor-ladder criteria, governance review cadence, and community meeting documentation. Maintainer diversity is explicitly acknowledged as an ongoing objective, with a target of removing single-organization majority representation before applying for CNCF Graduation. Could you please provide the final validation and merge this governance review? One older |
The governance review required in the issue#2035
Draft notes here: https://hackmd.io/@krol/SJLahh_9Wg
/closes #2035