← Back to team overview

tomdroid-dev team mailing list archive

Re: Owner of branches


Hi Koichi,

On Tue, Sep 11, 2012 at 9:57 PM, Koichi Akabe <vbkaisetsu@xxxxxxxxx> wrote:

> Hi All,
> Please note that branches which are owned by tomdroid-dev are able to be
> accessed by all of tomdroid-dev members. This team is Open Team, so
> anybody can join in this team "without" maintainer's approvals.
> It has critical security risk, because it means all of launchpad users
> can rewrite or remove these branches.
> Please consider changing the owner to yourself and add tomdroid-dev to
> subscribers.

This was made on purpose so that everyone can collaborate and experiment
without preventing other members from fixing the occasional typo or doing
some minor improvements to someone else's branch. It is painful to branch
someone's branch only to add a NEWS entry or implement findbugs
recommandations. On top of that when you open the merge request you seem to
be stealing the show with your new minor changes on top of someone else'

The code that is shipped / released comes from the maintainers branches
where only tomdroid-maintainers can push / merge / commit code. At this
point, we assume maintainers do their due diligence when accepting code and
make sure that said code is not trojan-ized.

I think the current process is safe. I would advise to keep tomdroid
branches under the tomdroid-dev team.

Olivier Bilodeau <olivier@xxxxxxxxxxxxxxxxx>