Re: Team permissions cleanup on GitHub

Dear all,

a short update from my side: The three teams mentioned earlier have been 
deleted. I've created a JSON dump before, but I guess we will not need it.

Best,
bergi

Am 18.01.26 um 16:57 schrieb bergi:
> Dear all,
> 
> Due to recent npm and GitHub attacks, permissions across all 
> repositories were reviewed and checked for potential risks. In that 
> review, I identified areas needing attention, and so I did some and 
> cleanup actions to improve repository security.
> 
> - The "Core" team has 31 members and had admin rights in some repositories.
>    - There was never a clear definition of who should be on the core 
> team or of the core team's purpose.
>    - I removed the "Core" team from the repositories (data-model-spec, 
> dataset-spec, query-spec, rdf-js, rdfjs.github.io, types).
> - The "Bots" team had explicit read access to a repository.
>    - The only member is the W3C IRC Trackbot: https://github.com/trackbot
>    - Since all repositories are public, it's unnecessary to give read 
> access to a bot.
>    - I removed the "Bots" team from the repository (data-model-spec).
> - There is a team "SHACL UI" for the archived shacl-ui repository.
>    - That team should no longer be required.
> 
> These changes should not have any impact, as the repositories remain 
> open for anyone to create issues and pull requests. Maintainers of the 
> repositories should not be affected. However, please reach out to me if 
> you encounter any issues.
> 
> Further, I would like to delete the following unused teams:
> - "Bots"
> - "Core"
> - "SHACL UI"
> 
> Please send me a message if there are any objects. Otherwise, I will 
> delete the teams on 31st January 2026.
> 
> Best,
> bergi
> 

Received on Saturday, 7 February 2026 16:34:50 UTC