- From: bergi <bergi@axolotlfarm.org>
- Date: Mon, 19 Jan 2026 10:43:30 +0100
- To: Ruben Taelman <Ruben.Taelman@UGent.be>
- Cc: public-rdfjs <public-rdfjs@w3.org>
Hi Ruben, Am 19.01.26 um 09:24 schrieb Ruben Taelman: > Hi Thomas, > > Thanks for this effort, reviewing potential security vulnerabilities > is definitely a good thing. > > We should be careful though, as some people may loose access to > repos with this removal of the Core team. Most repositories still have users or teams assigned. Other cases are covered by being an owner of the organization. Since the repositories are open for everyone to create issues or PRs, only tasks like changing repository settings would be affected, and most users will not need that. But I can't rule out that someone requires higher privileges in a repository and got them through the Core team. Because of the team size and the admin permissions that were assigned in some cases, the risk was weighted higher for me in that case. Please reach out in that case, and sorry for any inconvenience. > For example, I was not part of the N3.js team, while I require > access to it. I just now added myself to that team to make sure it > remains accessible to me. I didn't change the N3.js team or the repository. All affected repositories have been mentioned in my previous mail. Your access to the N3.js repository was covered by the owner membership in the organization. But it's good that you added yourself to the N3.js team. I would like to add more transparency in the future by using public teams so everyone can see who the repository maintainer is. > I would also like add myself to the spec teams if that’s ok for you? Yes, please! > But in any case, I’m ok with removing the Core team. I just wonder > if the 31st of January may not be too soon given the significance. The Core team is not assigned anywhere anymore. Currently, there is no usage for it. And I will create a JSON dump before I delete it, in case we need the list of members again. I would like to make further cleanups and add more transparency. Teams with no actual usage are just confusing. Best, bergi > > Kind regards, Ruben Taelman > > > >> On 18 Jan 2026, at 16:57, bergi <bergi@axolotlfarm.org> wrote: >> >> Dear all, >> >> Due to recent npm and GitHub attacks, permissions across all >> repositories were reviewed and checked for potential risks. In >> that review, I identified areas needing attention, and so I did >> some and cleanup actions to improve repository security. >> >> - The "Core" team has 31 members and had admin rights in some >> repositories. - There was never a clear definition of who should >> be on the core team or of the core team's purpose. - I removed the >> "Core" team from the repositories (data-model-spec, dataset-spec, >> query-spec, rdf-js, rdfjs.github.io, types). - The "Bots" team had >> explicit read access to a repository. - The only member is the W3C >> IRC Trackbot: https:// eur03.safelinks.protection.outlook.com/? >> url=https%3A%2F%2Fgithub.com%2Ftrackbot&data=05%7C02%7CRuben.Taelman%40ugent.be%7Cce54704d2ed04297af9c08de56aa6313%7Cd7811cdeecef496c8f91a1786241b99c%7C1%7C0%7C639043486972030127%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=IKx5%2BZQOBeZXQbKLVm0%2BQ3%2B4lqpljI%2B01zcC1cTkphI%3D&reserved=0 >> - Since all repositories are public, it's unnecessary to give >> read access to a bot. - I removed the "Bots" team from the >> repository (data-model-spec). - There is a team "SHACL UI" for the >> archived shacl-ui repository. - That team should no longer be >> required. >> >> These changes should not have any impact, as the repositories >> remain open for anyone to create issues and pull requests. >> Maintainers of the repositories should not be affected. However, >> please reach out to me if you encounter any issues. >> >> Further, I would like to delete the following unused teams: - >> "Bots" - "Core" - "SHACL UI" >> >> Please send me a message if there are any objects. Otherwise, I >> will delete the teams on 31st January 2026. >> >> Best, bergi >> >
Received on Monday, 19 January 2026 09:43:47 UTC