Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Policy violation Outside Collaborators #173

Closed
allstar-app bot opened this issue Jul 30, 2021 · 23 comments
Closed

Security Policy violation Outside Collaborators #173

allstar-app bot opened this issue Jul 30, 2021 · 23 comments
Labels

Comments

@allstar-app
Copy link

allstar-app bot commented Jul 30, 2021

Security Policy Outside Collaborators is out of compliance, status:
Found 1 outside collaborators with admin access.

Issue created by Allstar. https://github.com/ossf/allstar

@allstar-app allstar-app bot added the allstar label Jul 30, 2021
@allstar-app
Copy link
Author

allstar-app bot commented Jul 31, 2021

Updating issue after ping interval, status:
Found 1 outside collaborators with admin access.

7 similar comments
@allstar-app
Copy link
Author

allstar-app bot commented Aug 1, 2021

Updating issue after ping interval, status:
Found 1 outside collaborators with admin access.

@allstar-app
Copy link
Author

allstar-app bot commented Aug 2, 2021

Updating issue after ping interval, status:
Found 1 outside collaborators with admin access.

@allstar-app
Copy link
Author

allstar-app bot commented Aug 3, 2021

Updating issue after ping interval, status:
Found 1 outside collaborators with admin access.

@allstar-app
Copy link
Author

allstar-app bot commented Aug 4, 2021

Updating issue after ping interval, status:
Found 1 outside collaborators with admin access.

@allstar-app
Copy link
Author

allstar-app bot commented Aug 5, 2021

Updating issue after ping interval, status:
Found 1 outside collaborators with admin access.

@allstar-app
Copy link
Author

allstar-app bot commented Aug 6, 2021

Updating issue after ping interval, status:
Found 1 outside collaborators with admin access.

@allstar-app
Copy link
Author

allstar-app bot commented Aug 7, 2021

Updating issue after ping interval, status:
Found 1 outside collaborators with admin access.

@slonka
Copy link
Member

slonka commented Aug 7, 2021

What can we do about it? Why isn't this issue actionable? @snowp can you help? (pinging you because the PR was merged by you)

@allstar-app
Copy link
Author

allstar-app bot commented Aug 8, 2021

Updating issue after ping interval, status:
Found 1 outside collaborators with admin access.

@snowp
Copy link
Contributor

snowp commented Aug 9, 2021

@jeffmendoza Can you advise here? The description isn't super clear

It might also be good to increase the ping interval, this is a bit spammy as is

@jeffmendoza
Copy link
Contributor

The idea here is that outside collaborators (non-org members) shouldn't be administrators on repos. Either they should be part of the org, or only have push access. Administrators can change security related settings like branch protection.

@snowp
Copy link
Contributor

snowp commented Aug 9, 2021

@alyssawilk @mattklein123 Can either of you check up on this? I don't think I have the visibility into the repo settings.

Maybe there is some bot with admin access?

@mattklein123
Copy link
Member

I think I fixed it. If there are any follow on permissions issues please let me know.

@allstar-app
Copy link
Author

allstar-app bot commented Aug 9, 2021

In compliance, closing.

@allstar-app
Copy link
Author

allstar-app bot commented Jan 20, 2022

Reopening issue. Status:
Did not find any owners of this repository
This policy requires all repositories to have an organization member or team assigned as an administrator. Either there are no administrators, or all administrators are outside collaborators. A responsible party is required by organization policy to respond to security events and organization requests.

To add an administrator From the main page of the repository, go to Settings -> Manage Access.
(For more information, see https://docs.github.com/en/organizations/managing-access-to-your-organizations-repositories)

Alternately, if this repository does not have any maintainers, archive or delete it.

@allstar-app
Copy link
Author

allstar-app bot commented Jan 21, 2022

Updating issue after ping interval. Status:
Did not find any owners of this repository
This policy requires all repositories to have an organization member or team assigned as an administrator. Either there are no administrators, or all administrators are outside collaborators. A responsible party is required by organization policy to respond to security events and organization requests.

To add an administrator From the main page of the repository, go to Settings -> Manage Access.
(For more information, see https://docs.github.com/en/organizations/managing-access-to-your-organizations-repositories)

Alternately, if this repository does not have any maintainers, archive or delete it.

@jeffmendoza
Copy link
Contributor

@mattklein123 This is a new policy, can you check that it is working correctly? Are there any users or groups assigned to this repo with "admin" permissions? Thanks!

@allstar-app
Copy link
Author

allstar-app bot commented Jan 23, 2022

Updating issue after ping interval. Status:
Did not find any owners of this repository
This policy requires all repositories to have an organization member or team assigned as an administrator. Either there are no administrators, or all administrators are outside collaborators. A responsible party is required by organization policy to respond to security events and organization requests.

To add an administrator From the main page of the repository, go to Settings -> Manage Access.
(For more information, see https://docs.github.com/en/organizations/managing-access-to-your-organizations-repositories)

Alternately, if this repository does not have any maintainers, archive or delete it.

1 similar comment
@allstar-app
Copy link
Author

allstar-app bot commented Jan 24, 2022

Updating issue after ping interval. Status:
Did not find any owners of this repository
This policy requires all repositories to have an organization member or team assigned as an administrator. Either there are no administrators, or all administrators are outside collaborators. A responsible party is required by organization policy to respond to security events and organization requests.

To add an administrator From the main page of the repository, go to Settings -> Manage Access.
(For more information, see https://docs.github.com/en/organizations/managing-access-to-your-organizations-repositories)

Alternately, if this repository does not have any maintainers, archive or delete it.

@mattklein123
Copy link
Member

I made a change which will hopefully fix this.

@allstar-app allstar-app bot reopened this Jan 25, 2022
@allstar-app
Copy link
Author

allstar-app bot commented Jan 25, 2022

Reopening issue. Status:
Did not find any owners of this repository
This policy requires all repositories to have an organization member or team assigned as an administrator. Either there are no administrators, or all administrators are outside collaborators. A responsible party is required by organization policy to respond to security events and organization requests.

To add an administrator From the main page of the repository, go to Settings -> Manage Access.
(For more information, see https://docs.github.com/en/organizations/managing-access-to-your-organizations-repositories)

Alternately, if this repository does not have any maintainers, archive or delete it.

@allstar-app
Copy link
Author

allstar-app bot commented Jan 26, 2022

Policy is now in compliance. Closing issue.

@allstar-app allstar-app bot closed this as completed Jan 26, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants