Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Describe dispute process #11

Open
4 tasks
scovetta opened this issue Feb 9, 2021 · 0 comments
Open
4 tasks

Describe dispute process #11

scovetta opened this issue Feb 9, 2021 · 0 comments

Comments

@scovetta
Copy link
Contributor

scovetta commented Feb 9, 2021

We need to describe the dispute process / workflow. If someone disagrees with a review (meaning, it conflicts with the OpenSSF code of conduct, contains false or misleading material, is inaccurate, requires additional important context, contains a 0-day, etc.) -- how can they dispute it?

Perhaps:

  • Step 1 - Open an issue with the details on the security-reviews project. Resolve it that way.
  • Step 2 - (If not resolved), open an issue on the tac project. Resolve it that way.

Do we need a way to privately handle disputes? If so, maybe we can set up a private OpenSSF mailing list?

I'm hoping these cases are few and far between, but we should table-top this to be sure we know it'll work.

We also have a more practical issue -- once a PR is raised, the issue should be considered public. We can't erase the content from the Internet, and we shouldn't try to do unnatural thing to the repository except for the most extreme cases.

  • Include dispute resolution in the tabletop exercise.
  • Consider a private mailing list for sensitive dispute resolution.
  • Create PR templates that make it clear what kind of content to accept/not accept.
  • Consider a PR build job that attempts to identify 0-day or inappropriate language and blocks the PR.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant