- From: Ruben Taelman <Ruben.Taelman@UGent.be>
- Date: Mon, 19 Jan 2026 08:24:01 +0000
- To: bergi <bergi@axolotlfarm.org>
- CC: public-rdfjs <public-rdfjs@w3.org>
- Message-ID: <113A23F1-4058-4F22-B2D3-8637B6051189@ugent.be>
Hi Thomas, Thanks for this effort, reviewing potential security vulnerabilities is definitely a good thing. We should be careful though, as some people may loose access to repos with this removal of the Core team. For example, I was not part of the N3.js team, while I require access to it. I just now added myself to that team to make sure it remains accessible to me. I would also like add myself to the spec teams if that’s ok for you? But in any case, I’m ok with removing the Core team. I just wonder if the 31st of January may not be too soon given the significance. Kind regards, Ruben Taelman On 18 Jan 2026, at 16:57, bergi <bergi@axolotlfarm.org> wrote: Dear all, Due to recent npm and GitHub attacks, permissions across all repositories were reviewed and checked for potential risks. In that review, I identified areas needing attention, and so I did some and cleanup actions to improve repository security. - The "Core" team has 31 members and had admin rights in some repositories. - There was never a clear definition of who should be on the core team or of the core team's purpose. - I removed the "Core" team from the repositories (data-model-spec, dataset-spec, query-spec, rdf-js, rdfjs.github.io, types). - The "Bots" team had explicit read access to a repository. - The only member is the W3C IRC Trackbot: https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Ftrackbot&data=05%7C02%7CRuben.Taelman%40ugent.be%7Cce54704d2ed04297af9c08de56aa6313%7Cd7811cdeecef496c8f91a1786241b99c%7C1%7C0%7C639043486972030127%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=IKx5%2BZQOBeZXQbKLVm0%2BQ3%2B4lqpljI%2B01zcC1cTkphI%3D&reserved=0 - Since all repositories are public, it's unnecessary to give read access to a bot. - I removed the "Bots" team from the repository (data-model-spec). - There is a team "SHACL UI" for the archived shacl-ui repository. - That team should no longer be required. These changes should not have any impact, as the repositories remain open for anyone to create issues and pull requests. Maintainers of the repositories should not be affected. However, please reach out to me if you encounter any issues. Further, I would like to delete the following unused teams: - "Bots" - "Core" - "SHACL UI" Please send me a message if there are any objects. Otherwise, I will delete the teams on 31st January 2026. Best, bergi
Received on Monday, 19 January 2026 08:24:09 UTC