!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

397 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.121 Servers

Load older messages


SenderMessageTime
18 Feb 2026
@julienmalka:matrix.orgJulienGreat thanks!10:03:17
@hexa:lossy.networkhexaWe need someone to update the RFC39 tooling. GitHub has deprecated the API we use to manage team members and the GitHub bindings (hubcaps) are unmaintained since 2020.16:22:33
@hexa:lossy.networkhexahttps://github.com/NixOS/rfc3916:22:41
@hexa:lossy.networkhexaalso all of the dependencies are stuck in like 201816:23:58
@emilazy:matrix.orgemilyI have some thoughts on the RFC 39 things I plan to post soon16:24:13
@hexa:lossy.networkhexaYou mean the process?16:24:38
@emilazy:matrix.orgemilyit is probably a bad idea to have a long-lived token that powerful lying around. it probably makes sense to do it from within GHA or to move to a more self-service model where any committer can invite people to the maintainers team and merging new maintainers blocks on that16:25:16
@emilazy:matrix.orgemily(I believe that the rfc39 bot could most likely arbitrarily make any GitHub user committer right now?)16:26:01
@hexa:lossy.networkhexaNo idea, I never looked at that token16:27:30
@hexa:lossy.networkhexaBut given that no bot account has the maintainer role on the maintainers team, probably16:27:54
@hexa:lossy.networkhexahm, it's an app apparently16:30:31
19 Feb 2026
@toonn:matrix.orgtoonn This comment does claim that the app only needs `Members: Read and Write` permissions, https://github.com/NixOS/rfc39/blob/master/src/main.rs#L42-L46. 14:08:00
@toonn:matrix.orgtoonn emily: I think that at least addresses your concern about permissions? 14:08:29
@emilazy:matrix.orgemilyI'm pretty sure "Members: Write" is the permission that lets you make anyone a Nixpkgs committer.14:11:04
@toonn:matrix.orgtoonn Ah, it's org-level, not team-level permissions? That makes sense, I guess. Wouldn't GHA require the same privilege level though? 14:14:54
@emilazy:matrix.orgemilyyeah, but all changes to our GHA machinery go through our normal review, and if tokens leak unexpectedly from GHA then GitHub has bigger problems 14:39:40
@hexa:lossy.networkhexaI'14:45:05
@hexa:lossy.networkhexa* I'm super fine with giving it up14:45:09
22 May 2021
@grahamc:nixos.org@grahamc:nixos.org set the history visibility to "world_readable".17:01:28
@grahamc:nixos.org@grahamc:nixos.org changed the room name to "" from "".17:01:28
@cole-h:matrix.orgcole-h joined the room.17:03:05
@andi:kack.itandi- joined the room.17:18:59
@sandro:supersandro.deSandro joined the room.17:21:35
@hexa:lossy.networkhexa joined the room.17:22:33
@7c6f434c:nitro.chat7c6f434c joined the room.17:24:51
@colemickens:matrix.orgcolemickens 🏳️‍🌈 joined the room.17:26:27
@qyliss:fairydust.spaceAlyssa Ross joined the room.18:02:00
@toonn:matrix.orgtoonn joined the room.18:54:47
23 May 2021
@lukegb:zxcvbnm.ninjalukegb (he/him) joined the room.00:25:48
@sternenseemann:systemli.orgsterni joined the room.00:32:36

Show newer messages


Back to Room ListRoom Version: 6