Feedback Requested: Migrating Critical Chocolatey Packages To Chocolatey Community? #1898
Replies: 6 comments 2 replies
-
Makes sense to me 👍 |
Beta Was this translation helpful? Give feedback.
-
Yes, that sounds great.
As far as I am aware, for
Yes, this is important security wise.
As far as I'm aware, most of the packages you mentioned are already maintained by members of the Chocolatey Team or via someone already involved in this repository. So I'm not quite sure how this is intended to increase the number of Community maintainers in this repository? |
Beta Was this translation helpful? Give feedback.
-
I'll leave that for @AdmiringWorm to answer.
The Chocolatey Team are, on the whole, not involved in this repository. Having those packages managed by the team means they will be more involved in the repository, and by extension I'd hope more involved with other packages in this repository. I've spoken to the team about the intentions around this. More activity would hopefully bring in other maintainers. I also have a plan to reach out to people to help with that. EDIT: Clarified that I'd spoken to the team out the intentions. |
Beta Was this translation helpful? Give feedback.
-
Thanks @TheCakeIsNaOH and @pascalberger for your input. As there haven't been any objections to this, I'll move forward in getting the packages migrated. |
Beta Was this translation helpful? Give feedback.
-
I created an issue based on this discussion for us to target with the packages that will be migrated/created here: #1904 |
Beta Was this translation helpful? Give feedback.
-
The packages mentioned in this discussion have all been migrated to this repository. As such, I will be closing this discussion now. |
Beta Was this translation helpful? Give feedback.
-
I have a proposal that I wanted to discuss with the Community here to find the best way to approach migrating critical Chocolatey packages to this repository.
Chocolatey CLI requires specific packages for it's package sources such as
ruby
,python
andwebpi
. There are also packages that are required for Chocolatey CLI features such asintunewinappyutil
. And packages required for Chocolatey products such asnexus
andjenkins
. Different maintainers are responsible for these packages.To ensure Chocolatey has a secure, trusted and well-defined package management process, we have had some discussions internally and wanted to understand what the Community thought of:
CODEOWNERS
file ensures that the maintainers best placed to review package changes can do so, providing a trusted and secure process for those critical packages.I see the benefits to the Community as
The two important things that I wanted to ensure from this is:
I believe this will provide both of those, and I hope that it will encourage other new and experienced maintainers to become involved too. I would really like to see this repository thrive, and I feel this is a good step on that path.
Please let me know your thoughts.
Beta Was this translation helpful? Give feedback.
All reactions