Skip to content

Conversation

@avivkeller
Copy link
Member

Fixes #4
Fixes #21

cc @nodejs/web @nodejs/security-wg - Feel free to modify this file with additional permissions and/or changes

Copilot AI review requested due to automatic review settings September 10, 2025 01:06
@avivkeller avivkeller requested a review from a team as a code owner September 10, 2025 01:06
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR creates a comprehensive permissions documentation file that maps access levels for repositories, external services, and access tokens across different Node.js web teams and roles.

  • Introduces a structured permissions matrix documenting access levels for 9 repositories across 5 different team roles
  • Documents external service permissions for 7 services including Cloudflare, Vercel, and Sentry
  • Creates an access tokens section tracking service account credentials and their permissions

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@avivkeller
Copy link
Member Author

I added everything I am aware of, however, there may be inaccuracies

Copy link
Member

@AugustinMauroy AugustinMauroy left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing piece:

  • npm publish oidc (I think it's owned by tsc)
  • maybe not in this doc but it's "related" list which npm package we publish.

@AugustinMauroy
Copy link
Member

Btw thanks aviv to tackle it 🫶🏻

@avivkeller avivkeller mentioned this pull request Sep 11, 2025
@ovflowd
Copy link
Member

ovflowd commented Sep 21, 2025

bump, @avivkeller

@avivkeller avivkeller requested a review from ovflowd September 21, 2025 13:44
@ovflowd
Copy link
Member

ovflowd commented Sep 21, 2025

cc @nodejs/web-infra can y'all do a last review here to see if I missed anything, specifically on repo perms?

@avivkeller
Copy link
Member Author

cc @nodejs/web-infra can y'all do a last review here to see if I missed anything, specifically on repo perms?

fwiw I pulled directly from https://github.com/orgs/nodejs/teams/web/repositories

Copy link
Member

@ovflowd ovflowd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SGTM!

@avivkeller avivkeller added this pull request to the merge queue Sep 22, 2025
Merged via the queue into main with commit 9a38725 Sep 22, 2025
4 checks passed
@avivkeller avivkeller deleted the permissions branch September 22, 2025 17:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Document list of repositories owned by us and their purpose and brief intro Documenting our Bots

6 participants