<div dir="ltr">This PUP has been merged. I’ll send out the initial announcement in a new thread in the next few days. This announcement will include the date when we plan to enable the 2FA requirement.<div><br></div><div>Thanks.<br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><br></div><div>David<br></div></div></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr">On Mon, Aug 20, 2018 at 11:04 AM Jeff Ortel <<a href="mailto:jortel@redhat.com">jortel@redhat.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div text="#000000" bgcolor="#FFFFFF">
+1<br>
<br>
<div class="m_1461512891419100758moz-cite-prefix">On 08/15/2018 01:10 PM, David Davis
wrote:<br>
</div>
<blockquote type="cite">
<div dir="ltr">Thanks everyone for the feedback. I have opened a
PR for PUP-7 which (if approved) will require 2FA for the Pulp
organization in Github:
<div><br>
</div>
<div><a href="https://github.com/pulp/pups/pull/14" target="_blank">https://github.com/pulp/pups/pull/14</a></div>
<div><br>
</div>
<div>Feedback welcome. Also, I'd like to call for a vote by
August 27, 2018. Per PUP-1[0], are the voting options:</div>
<div><br>
</div>
<div>
<div>+1: "Will benefit the project and should definitely be
adopted."</div>
<div>+0: "Might benefit the project and is acceptable."</div>
<div>-0: "Might not be the right choice but is acceptable."</div>
<div>-1: "I have serious reservations that need to be thought
through and addressed."</div>
<div><br>
</div>
<div>[0] <a href="https://github.com/pulp/pups/blob/master/pup-0001.md" target="_blank">https://github.com/pulp/pups/blob/master/pup-0001.md</a></div>
<div>
<div dir="ltr" class="m_1461512891419100758m_1814242313330830155gmail_signature">
<div dir="ltr">
<div>
<div dir="ltr">
<div>
<div dir="ltr">
<div><br>
</div>
<div>David<br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<br>
</div>
</div>
<br>
<div class="gmail_quote">
<div dir="ltr">On Wed, Aug 1, 2018 at 3:00 PM David Davis <<a href="mailto:daviddavis@redhat.com" target="_blank">daviddavis@redhat.com</a>> wrote:<br>
</div>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">+1 to opening a PUP. Seems like that’s the best
way to document the policy. I will start working on this.<br clear="all">
<div>
<div dir="ltr" class="m_1461512891419100758m_1814242313330830155m_-4774678478724338528m_-4172299435731728310m_7653614178531068772gmail_signature" data-smartmail="gmail_signature">
<div dir="ltr">
<div>
<div dir="ltr">
<div>
<div dir="ltr">
<div><br>
</div>
<div>David<br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<br>
</div>
<br>
<div class="gmail_quote">
<div dir="ltr">On Mon, Jul 30, 2018 at 2:21 PM Brian
Bouterse <<a href="mailto:bbouters@redhat.com" target="_blank">bbouters@redhat.com</a>>
wrote:<br>
</div>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">
<div>+1 to requiring it. I also already have it enabled.
Would it be possible to either (a) turn this into a
short pup and call for a vote or (b) add a date to
close this email thread decision by?</div>
<div><br>
</div>
<div>Let me know if I should help write/review any.<br>
</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Sat, Jul 28, 2018 at 6:09
AM, Tatiana Tereshchenko <span dir="ltr"><<a href="mailto:ttereshc@redhat.com" target="_blank">ttereshc@redhat.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">+1, enabled.<br>
</div>
<div class="m_1461512891419100758m_1814242313330830155m_-4774678478724338528m_-4172299435731728310m_7653614178531068772m_-7099977895437955712HOEnZb">
<div class="m_1461512891419100758m_1814242313330830155m_-4774678478724338528m_-4172299435731728310m_7653614178531068772m_-7099977895437955712h5">
<div class="gmail_extra"><br>
<div class="gmail_quote">On Fri, Jul 27, 2018
at 12:02 AM, Dennis Kliban <span dir="ltr"><<a href="mailto:dkliban@redhat.com" target="_blank">dkliban@redhat.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">+1, but I already have it
enabled. <br>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Thu, Jul 26,
2018 at 3:53 PM, David Davis <span dir="ltr"><<a href="mailto:daviddavis@redhat.com" target="_blank">daviddavis@redhat.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">I got a notification
from another organization I am a
member of on Github[0] that they
are going to require Two Factor
Authentication[1] in response to
recent news about some malicious
code being shipped in a
compromised npm package[2].
<div><br>
</div>
<div>We are vulnerable to having
malicious code deployed to PyPI
if one of our Github accounts is
compromised. Thus, I wonder if
we should also require that
people with a commit bit have
Two Factor Authentication
enabled.
<div><br>
</div>
<div>Thoughts?<br>
<div><br>
</div>
<div>[0] <a href="https://community.theforeman.org/t/require-2fa-for-github-organization-members/10404" target="_blank">https://community.theforeman.org/t/require-2fa-for-github-organization-members/10404</a><br clear="all">
<div>
<div dir="ltr" class="m_1461512891419100758m_1814242313330830155m_-4774678478724338528m_-4172299435731728310m_7653614178531068772m_-7099977895437955712m_5646608958576497197m_5807261843911257054m_-8136455174575536232gmail_signature">
<div dir="ltr">
<div>
<div dir="ltr">
<div>
<div dir="ltr">
<div>[1] <a href="https://help.github.com/articles/requiring-two-factor-authentication-in-your-organization/" target="_blank">https://help.github.com/articles/requiring-two-factor-authentication-in-your-organization/</a></div>
<div>[2] <a href="https://www.theregister.co.uk/2018/07/12/npm_eslint/" target="_blank">https://www.theregister.co.uk/2018/07/12/npm_eslint/</a></div>
<span class="m_1461512891419100758m_1814242313330830155m_-4774678478724338528m_-4172299435731728310m_7653614178531068772m_-7099977895437955712m_5646608958576497197m_5807261843911257054HOEnZb"><font color="#888888">
<div><br>
</div>
<div>David<br>
</div>
</font></span></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<br>
_______________________________________________<br>
Pulp-dev mailing list<br>
<a href="mailto:Pulp-dev@redhat.com" target="_blank">Pulp-dev@redhat.com</a><br>
<a href="https://www.redhat.com/mailman/listinfo/pulp-dev" rel="noreferrer" target="_blank">https://www.redhat.com/mailman/listinfo/pulp-dev</a><br>
<br>
</blockquote>
</div>
<br>
</div>
<br>
_______________________________________________<br>
Pulp-dev mailing list<br>
<a href="mailto:Pulp-dev@redhat.com" target="_blank">Pulp-dev@redhat.com</a><br>
<a href="https://www.redhat.com/mailman/listinfo/pulp-dev" rel="noreferrer" target="_blank">https://www.redhat.com/mailman/listinfo/pulp-dev</a><br>
<br>
</blockquote>
</div>
<br>
</div>
</div>
</div>
<br>
_______________________________________________<br>
Pulp-dev mailing list<br>
<a href="mailto:Pulp-dev@redhat.com" target="_blank">Pulp-dev@redhat.com</a><br>
<a href="https://www.redhat.com/mailman/listinfo/pulp-dev" rel="noreferrer" target="_blank">https://www.redhat.com/mailman/listinfo/pulp-dev</a><br>
<br>
</blockquote>
</div>
<br>
</div>
</blockquote>
</div>
</blockquote>
</div>
<br>
<fieldset class="m_1461512891419100758mimeAttachmentHeader"></fieldset>
<br>
<pre>_______________________________________________
Pulp-dev mailing list
<a class="m_1461512891419100758moz-txt-link-abbreviated" href="mailto:Pulp-dev@redhat.com" target="_blank">Pulp-dev@redhat.com</a>
<a class="m_1461512891419100758moz-txt-link-freetext" href="https://www.redhat.com/mailman/listinfo/pulp-dev" target="_blank">https://www.redhat.com/mailman/listinfo/pulp-dev</a>
</pre>
</blockquote>
<br>
</div>
_______________________________________________<br>
Pulp-dev mailing list<br>
<a href="mailto:Pulp-dev@redhat.com" target="_blank">Pulp-dev@redhat.com</a><br>
<a href="https://www.redhat.com/mailman/listinfo/pulp-dev" rel="noreferrer" target="_blank">https://www.redhat.com/mailman/listinfo/pulp-dev</a><br>
</blockquote></div>