Skip to content

feat(perms): log all permissions and access - #41

Merged
avivkeller merged 15 commits into
mainfrom
permissions
Sep 22, 2025
Merged

feat(perms): log all permissions and access#41
avivkeller merged 15 commits into
mainfrom
permissions

Conversation

@avivkeller

Copy link
Copy Markdown
Member

Fixes #4
Fixes #21

cc @nodejs/web @nodejs/security-wg - Feel free to modify this file with additional permissions and/or changes

Copilot AI review requested due to automatic review settings September 10, 2025 01:06
@avivkeller
avivkeller requested a review from a team as a code owner September 10, 2025 01:06

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR creates a comprehensive permissions documentation file that maps access levels for repositories, external services, and access tokens across different Node.js web teams and roles.

  • Introduces a structured permissions matrix documenting access levels for 9 repositories across 5 different team roles
  • Documents external service permissions for 7 services including Cloudflare, Vercel, and Sentry
  • Creates an access tokens section tracking service account credentials and their permissions

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

Comment thread PERMISSIONS.md Outdated
Comment thread PERMISSIONS.md Outdated
Comment thread PERMISSIONS.md Outdated
@avivkeller

Copy link
Copy Markdown
Member Author

I added everything I am aware of, however, there may be inaccuracies

@AugustinMauroy AugustinMauroy left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing piece:

  • npm publish oidc (I think it's owned by tsc)
  • maybe not in this doc but it's "related" list which npm package we publish.

Comment thread PERMISSIONS.md
Comment thread PERMISSIONS.md Outdated
Comment thread PERMISSIONS.md Outdated
Comment thread PERMISSIONS.md
@AugustinMauroy

Copy link
Copy Markdown
Member

Btw thanks aviv to tackle it 🫶🏻

Comment thread PERMISSIONS.md Outdated
@avivkeller avivkeller mentioned this pull request Sep 11, 2025
Comment thread PERMISSIONS.md
Comment thread PERMISSIONS.md
Comment thread PERMISSIONS.md
Comment thread PERMISSIONS.md Outdated
Comment thread PERMISSIONS.md Outdated
Comment thread PERMISSIONS.md Outdated
Comment thread PERMISSIONS.md Outdated
Comment thread PERMISSIONS.md Outdated
Comment thread PERMISSIONS.md Outdated
@ovflowd

ovflowd commented Sep 21, 2025

Copy link
Copy Markdown
Member

bump, @avivkeller

avivkeller and others added 4 commits September 21, 2025 09:38
Co-authored-by: Matt Cowley <me@mattcowley.co.uk>
Co-authored-by: Matt Cowley <me@mattcowley.co.uk>
Co-authored-by: Matt Cowley <me@mattcowley.co.uk>
@avivkeller
avivkeller requested a review from ovflowd September 21, 2025 13:44
Comment thread PERMISSIONS.md Outdated
Comment thread PERMISSIONS.md Outdated
Comment thread PERMISSIONS.md Outdated
@ovflowd

ovflowd commented Sep 21, 2025

Copy link
Copy Markdown
Member

cc @nodejs/web-infra can y'all do a last review here to see if I missed anything, specifically on repo perms?

@avivkeller

Copy link
Copy Markdown
Member Author

cc @nodejs/web-infra can y'all do a last review here to see if I missed anything, specifically on repo perms?

fwiw I pulled directly from https://github.com/orgs/nodejs/teams/web/repositories

@ovflowd ovflowd left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SGTM!

@avivkeller
avivkeller added this pull request to the merge queue Sep 22, 2025
Merged via the queue into main with commit 9a38725 Sep 22, 2025
4 checks passed
@avivkeller
avivkeller deleted the permissions branch September 22, 2025 17:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Document list of repositories owned by us and their purpose and brief intro Documenting our Bots

6 participants