Re: merging PRs - branch protection questions

2022-04-16 Thread Ralph Goers
Somehow I replied on the wrong thread. I was OK with requiring PRs that I could self approve. I was not OK with requiring every PR require multiple approvals. Ralph > On Apr 15, 2022, at 3:24 PM, Volkan Yazıcı wrote: > > I couldn't introduce branch protection (aka. RTC review-then-commit) sin

Re: merging PRs - branch protection questions

2022-04-15 Thread Volkan Yazıcı
Thanks for the heads up Matt! Have done it. On Fri, Apr 15, 2022 at 8:37 PM Matt Sicker wrote: > Volkan, if you'd like to continue using git commit sigs, you should > also upload your public GPG key to your GitHub account so that it can > verify your commits, too. Otherwise, GitHub doesn't exact

Re: merging PRs - branch protection questions

2022-04-15 Thread Matt Sicker
Volkan, if you'd like to continue using git commit sigs, you should also upload your public GPG key to your GitHub account so that it can verify your commits, too. Otherwise, GitHub doesn't exactly import GPG keys from the public web of trust; they only use GPG keys you specify in your profile (whe

Re: merging PRs - branch protection questions

2022-04-15 Thread Matt Sicker
We have some blockers to strictly enforce RTC such as having enough volunteer time to provide timely PR reviews along with an unnecessarily long CI build time (especially when building locally with all tests now takes about 15 minutes versus 45 minutes in CI). I think we've mostly settled on using

Re: merging PRs - branch protection questions

2022-04-15 Thread Gary Gregory
Note that nothing is preventing people who like RTC to do so. Gary On Fri, Apr 15, 2022, 09:25 Volkan Yazıcı wrote: > I couldn't introduce branch protection (aka. RTC review-then-commit) since > Gary was strongly against it. It was just me, Matt, and Carter supporting > the idea; Ralph was also

Re: merging PRs - branch protection questions

2022-04-15 Thread Volkan Yazıcı
I couldn't introduce branch protection (aka. RTC review-then-commit) since Gary was strongly against it. It was just me, Matt, and Carter supporting the idea; Ralph was also sort of against it. You can search the archives for details. I couldn't even introduce commit signatures. Sigh... On Fri, A

merging PRs - branch protection questions

2022-04-14 Thread Remko Popma
I remember we discussed changing our development process to use PRs instead of committing directly to the release branches. This was part of trying to increase our security score, especially the Branch Protection part in scorecard (https://github.com/ossf/scorecard/blob/main/docs/checks.md). Quest