Video summary
The Hiero Technical Steering Committee meeting convened to address critical updates regarding community events and governance structures, starting with announcements from Michael Kendo about upcoming content from the Wear Evo panel in Las Vegas and an AI-powered development workshop led by Angelina. A major focus of the session was the process for filling three open committee seats, where the group debated two scenarios after clarifying that the TSC-voted position must be filled from a pool of maintainer nominees. The committee ultimately selected the second scenario, establishing a timeline with nominations running from August 25 to September 8, followed by parallel ballots where maintainers vote for two candidates and the TSC selects a third from the remaining pool.
In addition to election logistics, the committee reviewed a proposal to remove references to "Hideera" from the codebase to reinforce Hiero's independence, though this decision was paused to allow for a week-long review period to address concerns about potential typos and alignment with LFDT governance standards. The discussion also shifted toward enhancing security protocols for repository maintainership, including the implementation of new tools to scan pull requests for malicious code and creating a functional distinction between "committer" and "maintainer" roles to separate trusted from untrusted contributors. While acknowledging that GitHub's native system limits direct role separation, participants agreed that custom rules could enforce different approval thresholds to bolster security without becoming bottlenecks during the onboarding of new community members.
Jesse requested committer status for the Hiero JavaScript SDK, which sparked a broader conversation about qualification requirements and security frameworks for accessing sensitive repositories. Sophie presented a proposal outlining general pillars for qualifications to provide clearer guidance, while Keith emphasized the necessity of establishing secure workflows and trust mechanisms before granting access to core repositories. The committee agreed not to let these ongoing discussions block current contributions but decided to address the comprehensive security and qualification frameworks in future meetings, with Keith scheduled to present his thoughts next week alongside Sophie's discussion on contributor qualifications.
The meeting concluded with confirmation that key participants, including Sophie, Jessica, and the speaker, had already met Jesse in person at the Hiero community day, reinforcing the collaborative nature of the group as they balance rapid growth with necessary security measures. By adopting the specific election scenario and pausing the Hideera reference removal for further review, the committee ensured a structured path forward that respects both technical cleanliness and governance standards. Ultimately, the session reinforced a commitment to building a secure, inclusive ecosystem where new contributors can be onboarded efficiently while maintaining high standards of trust and security through carefully defined roles and approval processes.
Read the full video transcript
Hey Leman.
>> Hey. How's it going?
>> Good. Good morning.
>> Good morning.
I was just this morning reading your
hip. It looks great.
>> Oh, you like it? Okay, cool. Yeah.
>> Yeah.
>> Good. Yeah. I was I guess I'm gonna
bring that up. Um
>> Oh, yeah.
>> Yeah.
>> Yeah. Looks good to me.
>> Thanks.
Are you going to um
uh Denver?
>> I am. That'll be fun.
>> Yeah. Cool.
>> Yeah, it'd be good to see you there.
>> Yeah, it' be good to see you, too.
If you the the girls um my girls have
started school, they're four now.
>> When I started, they were little babies.
>> Wow.
>> And now they're all growing up and going
off to school.
>> Amazing.
>> I know.
>> Yeah.
>> Giving us the anxiety. [laughter]
>> Isn't it amazing how fast time flies?
>> It's crazy. And I've been really
reflecting on it past couple days.
It's just, you know, I thought, you
know, learning stuff about ancient Rome
and thinking about how they they just
live their own lives just like we are
living our lives here and so much time
has passed and
>> it makes you wonder about, you know, the
decisions that you make. How
consequential are they? you know how we
uh how I like you know put so much
gravity into stuff and I'm like you know
[laughter]
in a thousand years
>> that thing I stressed over a thousand
years
>> exactly [laughter]
>> Yep. Yep. Exactly.
And then it's like what what is really
important and what should
>> you know what should I be stressing
about or
>> not stress question. Yeah.
>> Yeah.
>> I agree.
>> What do you think it is?
>> Me. Oh, I'm following the Lord. Um, I
think Jesus has called me to live a life
for him. That's what matters.
>> Yeah. Um,
yeah. Cool. We'll we'll talk about that.
What that work looks like, you know, in
Denver if you want.
>> Yeah. Yeah. Sure.
>> Cool. Yeah. It's exciting.
All
right. Hello everybody.
Hello.
Hi
So let's wait some more minutes for all
the people to attend.
Um happy to already send the link to the
agenda here in the chat. It's um that
one
and I will send a notification in the
different channels that TSC starts.
Good. So, let me
share the agenda for today with you.
>> Good morning.
So more and more people coming up. Um
but we have a super packed agenda today.
Um so I will directly start with the
introduction.
Um so welcome to the HYROT TSC call. Um
this is the call of the technical
steering committee of the hyro project
and it's a public call which means um
everybody is welcome to join this call
or any other of our TC uh TSC calls we
are doing to be fair every call in the
hyro project is is a public call. We
have a public agenda. You can find links
in in the minutes of those calls on our
website or on GitHub where you can find
information about all the different
meetings we are doing and have scheduled
and um if you miss a meeting most of
them I even recorded. So if you go into
the Kaganda and and go back in in time
to like last week um you can find an
overview um of a recording and an
overview of of the minutes. Some of them
are II based. Um, which gives you a good
expression on what happened in in the
past. And um
oh yeah and before I miss that and since
we do that as open as possible and and
want to ask you all to bring in your
thoughts and and to discuss with us we
have two roots which is the um antitrust
policy of the Venox Foundation and the
code of conduct of the Venu Foundation
and with that let's jump to the agenda.
agenda for today. So as said we have a
quite packed agenda. I I assume we will
not make it through all the topics.
Let's see how far we can come. So uh
since some time I start each of the TSC
meetings with a short recap of what
happened in the previous TSC meeting and
and last week um we had a final voting
on a new proposal what brings in
additional um repositories to the solar
project to make it more more flexible
and provide um more flexible builds.
regarding um subcomponents of a network
when you for example want to depend on
on a branch and and so on. Next to that,
we voted on on another hip and had some
discussions regarding
um the maintainer
and um commit how to say it like um with
what what those people should do and
what we expect um from maintainers and
committers in the project. Um we had a
short overview about the reaction that
is happening soon and we discussed about
um the TSC internal channel which
currently is on um sak which is sub
optimal
um and we decided that we will give
discord a try. Um I already tried it
this week to to set it up. Some things
failed. So I wrote a message to to RFDT
earlier today just for you, Brandon. So
So I'm on it. I already have a TLC
private channel in Discord. It looks
like I failed to invite people to it.
That's that's the current state, but but
I'm trying to to get this up and and
running.
Okay. Um coming to the agenda for this
week. First of all, we have the any
updates and events. um from the
community which is normally the point
where I ask everybody here in the call
if you have some news about a project if
you have some
news about any any upcoming events that
are happening where hyro is a topic
where maybe you give a session about
hyro and so on. Um before we come to the
one that is mentioned here, um I want to
ask the the audience of of this call if
somebody would like to add something
here, has something to share.
I see Michael Kendo had shared something
in um the chat saying over the coming
days hashcraft online will be publishing
clips from the wear evo panel in Las
Vegas first one can be shown on X. So
that was an event we had in the near
past, right? Where um Michael had a
session on where Evo I know Jessica had
a session too and it looks like um yeah
some of those clips now make it to
social media. Thanks for sharing
Michael. Um the other news we have is
the um workshop that NG is doing on AI
um which is maybe like a subtopic of of
Hyrole um because it's mostly about AI
power tools and how you can use it for
development. But what Angelina is doing
here is she shows it on the Hierro
project and shows what what she did on
the Hierro project where we even today
if if we come to that point um have a
short um
introduction to to something new as said
we have a lot of topics. So let's move
forward. Um yeah, one one topic I would
bring to this group is since the
elections for the TSC are coming and
starting today nominations are open um
you will see that the oops not open in a
new window then you don't see it that
the big text here is is a ring that
gives an overview
about the um
erection and um nomination phase. I
assume Jessica has some things to share
on on that because we had some internal
discussions. Um but why I mentioned it
now is because all maintainers are able
and contributors are able to to vote on
it. Um and that is why um some people
from the community um seen that as a
good point to do some some cleanup of
our maintainer and and committer groups
and thanks to the analytics project that
are currently being created at at
hierohhackers. um you get quite good
information about um are there any any
accounts who have not contributed for a
long time and so on. And um what
happened is that pull requests have been
created um that do the opposite of
nominating new maintainers or committers
but removing such people and um as far
as I know if if they took like my my
suggestion so I have not created it but
um Sophie is here. So Sophie, this is
like everybody who has not done any
contribution in 2026, right?
>> Um that was Jessica's pull request
initially. These ones are
for a given
uh team collection.
>> Okay.
If you've not been inactive in the
repositories that you have access to.
>> Sure. But but again since since the
beginning of ah for 6 months ah okay
okay because I I did the suggestion to
say like since the beginning of the year
because this is even even a little bit
longer than than 6 months. Um any anyway
[clears throat] so my my hope is and you
see that this already happened that
people came to it and said oh no we have
here a person that should stay for sure
and I mean if maintainer says that
that's totally fine right so our idea
here is not to show who must be removed
it's more like hey maintainers have a
look those are the statistics um so
please check it and maybe I already
answered keys your question Oh, because
I saw your hand up and and and down
again.
>> Yeah. I I I just cuz we we talked about
this yesterday with Sophie and just as a
reminder, the policy is um someone can
be removed if they're not active for 6
months and they cannot be contacted. So,
yeah. Yeah. But if if this is just a
like guidance, then then that's I mean
obviously every project can make their
own decisions about adding or removing
maintainers. So I just wanted to say
that that's the policy.
>> Yeah. Yeah. And and I totally agree. And
so for me this is not like everybody now
need to v vote plus one and all those
people need to be deleted. This is more
like okay here are you know um the
changes that if we would take this
restrict um how it would look like and
everybody is fine and that's already
happened to say like oh no this this
person should stay and so on and so on.
Diane,
>> so um thanks thanks for the explanation
and thanks Keith for the clarification.
could um could it looked like um and the
only reason I tweaked to this was cuz
yesterday morning I looked at all the
messages the um the the did SDK it
looked like a number of us were removed
um for the the SDK for the did did work
and if you could just go to that screen
on
[sighs] let me see if I can find it
again there were a lot of
>> did SDK Python or did SDK script
>> just the did SD
K stuff and Alexander might be on here
too because I saw that he was also
removed.
>> Yeah. Yeah, that should not happen. So,
um
>> yeah.
>> Um
okay, I assume this one is the not the
one.
>> Yeah, maybe. Okay, so where you go where
it says use my name as an example. So
explain um
>> is no longer a member of that king. So
is that the configuration change that's
proposed or is that already
>> proposed? No, no, no, no, no, no. That
is proposed and now the team could vote
on it or and and this is the team right
here. You see the key
>> and when you say hey please so like uh
when you write Diane should stay that's
just good enough then it will directly
done it not even [clears throat] proved
or or discussed or whatever right this
is just hey this is
>> how it could look like and now please
clean up so so that we can update each
and everyone
>> uh each and every project. Yeah.
>> And I'm I'm using myself as an example
because you know this is and especially
for this project because we lost our
funding for working on it. Yeah.
>> And we became inactive. However, we are
working mightily in the background to
get funding for it. So I prefer not to
have Alexander and other folks re
removed from it until we are sure we're
not going to get funding. But it looks
like we will shortly. So um but and it
didn't make me crazy or anything like
that or paranoid. was good to see. Um,
but I just it looked a little bit in the
the wording of that that it was um that
they had been removed and I was
concerned.
>> No. Yeah. Yeah. And and and I agree with
that. So um that is not the case. This
is always like a preview what would
happen if this one is merged.
>> Okay, that's that's what I wanted.
>> The validation. Yeah. and and please
stand up and say, "Hey, please don't
delete me." That's totally fine, right?
That's that's what we want because we
want to remove the persons who are
really not active anymore. But from for
many projects like so Sophie who did
this has no idea who those persons are.
So it's now done by mass and now it's up
to you to to clean it up.
>> And it's really good work, Sophie. So
keep it up and thank you. Um, but yeah,
I just wanted I saw that Alexander was
on the call today, too, and I'm sure he
woke up yesterday thinking something
similar. So, um, yeah, I just wanted to
get that on. Cool.
>> Yeah, the the way the um configuration
document
is created, it's it's also difficult to
create these proposals.
Um, so as you've seen, you you may be
that there isn't like one SDK did team.
>> Yeah.
>> For example. So that that might be why
there are several
um several things.
>> Yes.
>> So I I've tried to group them by
um like the big team that controls the
sub teams if if that makes sense. Um but
yeah what what Hendrickk said is this is
just done from like a security
permission perspective in terms of if we
have granted rights permissions
um and if those permissions haven't been
used then there could be just a security
use case to clear them up but I don't
know about who a lot of these names are
or or what the intention behind anything
is. So I think um the the all these
things I typed them up manually but they
should really be saying very clearly
this is like a proposal um to change
these I haven't added my own rules so
it's just simply inactive or not
um you know so some people have
requested like re readding
uh certain managers or something that I
I'm not aware of so as as examples um
definitely so you can I I think you can
block the pull requests from merging.
>> Yeah.
>> By requesting changes if if that's
that's sort of what you want. Um I think
as a group of the maintainers you could
even close the pull request if you
disagree with the idea entirely. Um but
some of the um pull requests people have
just been making like suggestions to
individual members. Sometimes they're
suggesting more people to remove,
sometimes they're suggesting certain
people to be removed as well. And I
ideally I get like feedback from a lot
of the maintainers. So it's not not just
one maintainer's opinion. So I would
really appreciate like everyone taking a
look at that. This is just let's say a
security
permission
proposal, but it doesn't um you know
that's just one way of viewing things.
And it it does have to be voted by all
the maintainers anyway to be able to
pass.
>> Um, witch, you have hands up.
>> Yeah, I apologize for this. U Leman only
has six minutes left before he has to
leave
>> and uh we he really wanted to have an
opportunity to talk about his topic or
vote on it. But this is a great thing,
Sophie. And in fact, I'd like to if if
we can just switch gears for a moment,
we can come back to this.
>> Okay. Thank you. Yeah, I I already have
opened it and even if there are other
things up front, I would like to to jump
to this update on on HIP one. Um and um
I assume Michael Michael Gawa wants to
to give a presentation to it. Um,
so
>> yeah, can you can you just uh pull up
the PR? Um,
>> and I think what I can do is give me a
second. I can do it like this and like
this. Um,
>> I Yeah, just a I was just going to say a
couple quick things. um when we we we
made this migration uh from Hideera into
Hierro when when the codebase was
donated um for open-source uh practices
um and what happened in that migration
which is on me is that uh some of the
hideerod dependent language uh remained
in there. So this was caught and um this
PR this change is as an opportunity to
really kind of um get an understanding
of how this works and remove the Hideera
dependent language. Um so instead of
like talking about Hideera as the
network, it is a network. It is a it is
a like an instance of a hyroleddger and
what it essentially does now uh it's
going to describe what's already true.
So that you guys the TSC are the sole
authority for approving HIPS into hyro
and whether any network that includes
Hideera adopts a feature is is that
network's own decision and that's
independent in both directions. Um
>> yeah,
>> and there's also a section in the uh the
HIP template
uh for other networks so they can um add
that uh acceptance decision in there as
well.
>> I even want Yeah.
>> Yeah. Um so just some historical
background in 2024 the TSC we agreed, oh
yeah, we need to take this Hera stuff
out. We need to basically do what
Michael just did. and we all agreed on
it and then nobody actually ever did it.
Uh [snorts] so we've never approved HIPP
1. We've never made the changes we said
in 2024 we should and this cleans it up.
It makes it clear that Hierro is
independent of Hideera. It makes it
clear that Hideera is independent of
Hierro. Um so I do have to drop and I'm
sorry I have a thing I can't get out of.
But I just want to say yeah I I vote for
what Michael did and I think the TSC in
2024 would have voted for it if we had
voted. Uh but we just didn't vote back
then. So that's all I have to say.
Thanks.
>> Thanks, Leman.
>> Thanks, Lemon.
>> Um,
okay. So,
are there first of all any any questions
on that one?
>> Yeah. So, I had a question. Uh obviously
um uh other than some typos that we're
seeing on the screen here about Pyro
SDKs uh hero u the on the top which is
impact on SDKs.
>> Ah okay. Yeah. Okay. Yeah. the um
some of these changes were I mean
obviously were done as part of the move
to
um to LFDT.
So I I'll make sure that
you know true where there are some
references to a particular network like
Hideera
uh you know may not make sense but
making sure that we kind of diff through
this to make sure that uh that we
maintain kind of the integrity and kind
of reduce any avenues for forking that
might result.
>> Yeah. Absolutely. Absolutely. Maybe
maybe maybe adding adding some thoughts
on that. So for sure the goal here is
not to remove any
don't know the best English word
benefits or whatever that that Hideera
has. Right? So um it was never the goal
that Hideera somehow controlled Tairo or
Hyrule somehow controlled Hyera. was
from my point of view always a goal that
um hyro can be used for by anybody by by
any network. Um but we need to make sure
and that is even written in the charter
that um the Hideera network um as the
enterprise grade network that is that is
using Hyrule um stays safe which which
means um that if something comes up
maybe we need to have additional
configurations and and stuff like that
but we should try to avoid that. for
example, Hideera has I don't know that
the need to create their own repo to
fork something. So that for 100% should
not happen and and I hope this is for
phrased in a way that that um this is
clear. Diane,
>> I I was just going to say um it thanks
for for doing this. Um I I'd love to
take a a deeper look at it and review it
uh in in terms of the LFDT governance
and stuff that we've done in the past.
Um so and and maybe correct a few of the
typos too. So yeah.
>> Um yeah. So this this is an
it it's a governance kind of thing. So I
think we if we could take a minute and
not a minute but maybe a week and just
um review it. Um, and then I think that
the stuff about the SDKs could might be
a good clarification point to keep in um
a statement about how this would affect
the SDKs. But um yeah, so I think that's
you know that's that's my two cents is
if we can give give us ourselves a week
to to take a review of it then that
would be wonderful.
the the impact on the SDK part that is
in the HIP template and that serves as a
guide for people to submit HIPS. So
there's a section in there if something
touches an SDK and that uh mis that
misspell had had been there and and I
just corrected that.
>> Yeah, that's that's fine. Yeah, just
just a chance to uh if we got a chance
to read through this, it would be great
for people to have a comment period. Um,
>> and just to just to compare it maybe
with some of the other LFT governance
stuff, I don't see anything really
egregious in it at all. So, that's not
what I'm saying. But I think just a
chance to to look through it
would be great and have maybe a a
oneweek comment period before we
activate pull the trigger on it.
>> Um, I'm fine with everything. We can
even now, you know, scroll through it
and and have a look um up up to what you
want, what what other people from the
TSC want.
>> I mostly want more coffee and a chance
to read it. [laughter]
>> What is What is the West saying of you?
Um, I would say, yeah, it' be great to
to have a chance to read through it and
uh, yeah, just I I agree with what Diana
was saying.
>> I multitasking, but I I agree with Dan,
too. I think it's it's been a pretty
good precedent that, hey, if the vote
comes up for something, we usually take
a week to think about it and then we
vote the next week.
>> Right. Right. Sure.
Um
I let me put it here, right? Because um
when I did that
um
the link was not there. Now we have the
link here. Um so that everybody can can
have a look at it and um that maybe we
can vote then then next week on that
one. Okay to everybody.
>> Yep.
>> Okay. Um
next topic election and voting pro so
moving one back election and voting
process clarification. Um
that is Jessica you right?
>> Yes. Yes. Thank you so much. So this is
mostly um clarification on the actual
process because uh as you know today uh
the nominations have started are
officially open and they're going to be
running until August 25 sorry September
8th uh from from right now to September
8th. However given that we are going to
have uh we have three different seats uh
up for election. We have two maintainer
seats that uh maintainers are going to
be eligible to vote for and we have one
seat that the TSC is going to be voting
for. So, let me can you show the picture
that I sent you yesterday?
>> Sure. Give me a second. Let me just Oh,
I I assume I can just open a tab and
drag the picture into it because that is
Yeah. Yeah. That is a really good
>> um description out of it.
Yeah, thank you Chad GPD. [laughter] But
yeah, I tried to put it in in a visual
way so that people can can
>> Oh, what have I done?
>> Understand the two options that we have
here. So this is we need the TSC to vote
on one of these two scenarios and how
are we going to run elections. So um if
the I I think we do have quorum today.
So if we can make a decision today that
will be awesome. But let me explain the
two scenarios given the positions that
we have open. So the first scenario
elections start on the 25th which is
today and go until September 8th. And
nominations are going to be needing to
be filed as either a maintainer TSSE or
a TSSE voted seat depending on what the
person that is being nominated wants his
nomination to be voted by. he wants to
be voted by maintainers or he wants to
be voted by TSC. So depending on that
the nomination will be filed as such and
then from September 9 to September 20th
the two ballots run in parallel one
where maintainers vote on two maintainer
seats and another one where the TSC
votes on one uh TSC voted seat. So these
two ballots are running in parallel and
on September 22nd uh all the results are
announced. So that's one of the
scenarios. Uh and the TSC chair position
is basically the winner of the TSC voted
seat that will that will become the
winner of the TSC chair position.
And the second scenar Yeah. Hendrickk
you look like you have a question.
>> I I yeah I I would disagree. I would I
sorry when I look at this picture
somehow I have not seen the TSC chair
position. What is [laughter]
>> for the TSC chair I would not say like
the person who won the TSC voted seat
bot will become the TSC chair. I mean
that would mean that people who are
currently on the TSC would not be
allowed to to become the TSC chair. I I
would say that afterwards we do a
separated voting on on the
>> Okay. Okay. For both chair and co-chair,
right? Because you wanted a co-chair as
well. Okay. So, let's uh let's pretend
that little uh drawing at the bottom is
not there. But yeah, this is what
scenario one looks like. And and
scenario two, h this is a little bit
simpler. So basically we from August
25th to September 8th all nominations
are filed as equal like that you're just
going to be occupying a TSC maintainer
seat. That's all the nominate nominees
need to know. And then from September 9
to September 20th the first ballot runs
where maintainers select two candidates
from the list of candidates. And after
that, from September 21st to October
2nd, the second ballot where TSC members
vote for the third candidate runs, which
I think this is kind of similar to what
we did last year. Uh, and then on
October 6th, all the results are
announced. So, uh, take a look at these
two scenarios and if the TSC can help me
make, um, a decision here, uh, we would
like to post this in the blog,
[clears throat] uh, for people to know
what's going on.
>> Yes, Diane. So, in scenario two,
depending on how you read it, and I
really haven't had enough coffee yet
this morning, so I apologize.
>> [laughter]
>> um are the are the only people eligible
for um the TSC third candidate the
maintainer people who have nominated
themselves for a maintainer seat. So
that would the way I'm reading that
second scenario it could be interpreted
is that only maintainers are eligible.
M uh
>> no uh so on the the first the from
September 9 to September 20th mandainers
are eligible to vote uh first on two
candidates and then from the remaining
candidates that are not voted yet those
will be added in a second ballot and
that the TSC is going to be eligible uh
the TSC is going to be voting on a third
candidate for for that. So that that's
how the second scenario looks like. But
these are one ballot first and then the
other next.
>> Yeah. So yeah, this is what I'm trying
to get to the clarify. He's he's
scrolling to the section. So
>> yeah. Yeah. Yeah. Your question is about
um see
>> who's who who is the TSSE
allowed to vote? Is it just a pool of
maintainers that the TSSE is allowed to
vote from? I guess is
the way I read that diagram and I would
just want to go for the clarifying piece
here.
>> Let me see. I'm trying to find that
portion also in the charter. But yeah, I
mean it will be basically a a pool of
nominations of maintainers
>> and it so the pool that the TSC can
choose from for that TSC nominated state
is only people who are maintainers.
Correct. Is that what you're inter
interpreting it? Yes. And that's that's
what I was looking for.
>> Um,
>> so it's it could not be a a just a
community person or a community
participant.
>> I I want to make sure that that is also
in the charter that also matches the
charter. But I think that is correct. Uh
given that the maintain I think I
remember reading somewhere that the
>> it's not saying I I was not 100% sure
but it's not saying that
um on on the erect three TC members but
it not says three TC members who must be
maintainers. So I have readed so far
that the maintainers vote but the
nominee can be anybody but I'm not a
native speaker right that is that is how
how I um have interpreted it that's
that's why I do not see the problem
Diane sees
>> we we had also enduser seats in the past
that are not yet
>> up for elections just yet they're going
to be one of them I I believe is going
to up for elections in 2027. But yeah,
the these these two the seats that are
for election right now, there are two
maintainer seats and one DSC voted seat,
which I think that's the position that
Hendrik is occupying right now. So I I
assume that that position needs to be
also a maintainer or correct me if I'm
wrong,
>> it could be anybody in in theory. That's
that's the point. We do not define
>> yeah we do define who votes but but not
who must sit there and and the problem
with the left scenario what what I'm
seeing is that if you now nominate
yourself you need to decide do I
nominate myself for the one of the
maintainer TSC seats or for the TSC
>> voted seat or for both you know like uh
like which makes it quite complex and
since everybody is allowed to get
nominated or to nominate themselves. We
could do like scenario two with
you nominate yourself because everybody
can can get nominated and then the
maintainers vote for the um two
maintainer seats and from everybody who
has so we have two winners then but we
will have a couple of nominees who are
not winning that. So we only will
announce the true winner. no other
additional numbers or informations and
then the TSC can vote on from all the
nominations on a third person that that
will come into the TSC. The other point
is if we would not do it like that, we
would need another nomination phase um
after the the first bagot. Yeah.
>> Yeah.
>> Yeah. I think you explained it uh
perfectly. I mean yes uh all the
candidates that were not selected on the
first nomination will go for the second
one.
>> So the only change I would have in this
diagram then is in the second ballot
that it come that the seat is the third
candidate is elected from the remaining
pool
>> of uh TSC maintainer nominations
>> and that's that's that that would
clarify that for me. So if we're all on
the same page then we're all on the same
page. But in order to clarify that it
that kind of makes it like they could
randomly select a third candidate from
non-nominated people.
But yes, that's just
>> unless
unless we run in a situation where only
one nominee is remaining then
automatically would that person become
the TSC voted candidate? I mean I I hope
that's not the case but I think we'll
figure out once nominations
>> yeah are filed. Yeah.
>> Yeah. Then we have a bigger problem,
>> but I just think clarifying that second
and I know you'll have to run it through
Claude or something to add a little bit
of
>> Yeah.
>> Yeah. Absolutely.
>> From the remaining pool. I think we do
that um at the governing board level at
the LFDT if all the nominations are
there. There's a um we've got some they
have other votes too. So yeah, there's
that's the way I would think it would be
phrased is that from the remaining pool,
the third candidate is select selected.
>> Yeah.
>> Okay.
>> Yeah. As as on the tech I
>> Okay. Yeah.
>> How does the TSC like the timelines?
That is the most important thing. I
mean, I want to make sure that the TSC
uh likes the timelines here.
It works for me
and and I like the parallel ballots
personally.
>> Do you like the parallel ballots? Do you
like the first the first scenario?
>> So I do just because um I don't know it
it otherwise it it takes quite a long
time to go through all this. Are people
concerned that people will get confused
having two ballots going on at the same
time? Um,
go forward, Jessica.
>> No, I mean, I think I was going to
repeat something that you mentioned that
it's going to be confusing to for the
nominee to say, "Hey, do I want to run
for a TSA container or a TSC or both?"
>> I'm I'm okay with either one. I I I
don't have a preference between one and
two other than I just looked at scenario
one and I said, "Sure, we can get it all
done by the end of September. That
sounds great." Uh but if we want to do
it scenario two then um you know I'm
okay with that as
so I actually I would say like for the
voter it's no different right? So for
the people who who vote but um on on
scenario one let's say like who do we
have here? Michael Gaba. Let's say
Michael Gaba wants to to nominate
himself for for the TSC. In scenario
two, he just nominates himself. And
scenario one, he needs to decide, do I
nominate myself for the maintainer seat,
>> for the ESC seat, or in worse, for both?
And then both vote him, you know. So,
[clears throat]
>> yeah. Yeah. Yeah, that's true.
>> That's the point.
>> Yeah, that's the point.
>> Scenario two at least gives you a a
second attempt. [laughter]
>> If you lose the first round, you get to
go for the second one.
>> Yeah.
Okay. So, can can we do an official TSC
vote uh on the right scenario?
>> Yeah, sure. We can do it. Um, let's ask
Georgie.
>> Um, yeah, it's fine. I think Yeah,
>> perfect. Thank you, Richard.
>> Uh, I heard nothing. I've just seen that
you unmuted yourself. I assume it was a
yes.
>> Very fast. Is a very fast yes.
[laughter]
>> Okay, perfect. Thank you. Uh, Migan,
I cannot hear Migan. Can anybody?
>> No.
>> Okay, let's continue with with Michael
Caner. Megan, maybe you can write in the
chat.
>> Yeah, I think scenario two makes sense.
>> Yeah, Megan wrote scenario two makes
sense, too. And we have Aex. Yep. For
two.
>> Yeah, I do the same. So, we will take
scenario two and then we can update the
um erection um page here um with with
that put it in place and as said
starting from today um erections are
open. Um
actually that means um to to make that
clear it's uh what we are talking about
are the seats that currently um Richard
Stoan and I'm on all three are totally
fine to selfnominate theirel again um
but everybody else for sure can nominate
themselves too. you find the link here
um on top of the agenda to do so.
>> Thank you. Yeah, there's um sample
nomination there uh that you guys are
gonna find. So, yeah, looking forward
for that. And I think Diane has a
question. Do you have a question, Diane?
>> Nope. Um
I think I've stood Sorry.
Nope, I don't have a question. I did my
hand still up. Nope. I'm all
>> No problem. No problem.
>> There you go. Okay. Thank you. Thank you
so much everybody.
>> Perfect. Thank you Jessica for for
preparing that. And here you see the
example nomination. Okay. So next one is
and I don't know if we have an update on
that. Um we have um this git vote. Um
Tai is here. So Ty, can can you give an
update on on that one?
Uh yeah, so I've been talking with
Richard um and it does feel like there
might be some edits to it. So I think it
didn't pass twice now. Um so I'm going
to go and kind of rework some of the
wording and then hopefully when I come
back we can get quum and vote it
through. But um yeah, it's it's back at
me to edit the hip. So it's not coming
up for vote.
>> So yeah. So So Ty, what do you think
about if I close this issue and once you
are ready, you come back to us so that
it's not like every week on the agenda?
>> Would that work or do you prefer to have
it open and and come back to it like
already next week?
>> No, it's fine if you close it. Yeah.
Okay, good. Then we will wait um for any
any update on you. Um so the next is um
last week we already um showed that we
worked on this responsibilities of
committers and maintainers addition to
our documentation. I've seen some um
comments from from Diane. Thanks for
that. I tried to add all of them or said
or since they are like kind of follow up
things marked them as it it should
should be in follow up. So um I have not
seen any any other um concerns or
questions which gives me the impression
that mostly for everybody it's it's fine
because we have some follow-ups that
will come in in future. So if somebody
from from the TSC would be so friendly
to approve that one because then we can
get it in merch it and move um onward
from from that state. That would be
great. Um
good. So the next one is again Jessica
I think it's
>> I don't think it's Jessica. It's Jesse.
>> It's Jesse.
>> Yeah. No. So, yes, this this is
something that Jesse asked me to to put
on the TSC. Well, I I mentioned that I
will put it for him. So, is Jesse here?
>> Go ahead, Sophie. I think you you
probably have information.
>> I have a little bit of context, but
Jesse is on the call. Jesse, are you
able to speak?
>> Yeah.
So, I have a request of um becoming a
committer at the Hierro SDK, the
JavaScript SDK. And um I think I have
enough context about uh Hyro and its
technologies.
Uh I have been doing a few contributions
for
um a couple of months now.
And um yeah, I would like to know if
there is any specific kind of work that
I have to do in order to reach that
position. So uh ready to hear from the
maintainers
>> maybe. Oh Sophie, go go go forward.
last week. Um I think Hendrickk you
suggested to
as as a first point of contact if the
maintainers don't suggest the role to
you to instead bring up the issue on on
Discord and and suggest it to them to
see if that's something that they would
want to consider. I think Jesse has
already done that on Discord a few
months back because I think he he tagged
me in but I'm I'm not a maintainer of
the JavaScript SDK and I I don't have I
I don't know who is um so those options
are already exhausted in in in my view.
>> So that is maybe maybe saying something.
So that is exactly the point. Give me a
second keys. I just checked it up and I
was not aware of that last week when
when that question come up. when I said,
"Hey, please do it in Discord." Because
that has already been done early July,
like on on 6th July, um that question
came up and is unanswered um since
today. And then last week, Jessica wrote
that she will bring it to the TSC.
That's that's why I was thinking it's
Jessica's topic here. Um Keith, you have
hands up.
Um I think the path that we discussed
was junior committer and then committer.
Is that the path we want to follow?
>> It's up to the project. So I mean as a
project you can say somebody becomes a
junior committer or you can say oh there
was somebody who is not a junior
committer at all but worked on on the
project for some months already. So you
could make him directly a committer. So
the junior committ is something just we
added to make it more easy to people to
assign issues and stuff like that and
and that is what people mostly got after
I don't know like two weeks or or three
weeks in in in other repositories or
after two or or three PRs. Um I mean we
can have I have not done that to to be
fair. So we can have a a look since I've
seen the link here. Let's go to
maybe I I can cover two topics with one
stone. I I do maybe for the next TSC
Hendrickk can I present the uh security
designation presentation on making
certain repo
>> making certain repos security sensitive
and I mean this dovetails right into
this topic like Jesse I'm I'm sure like
uh you know it's wonderful we've gotten
your contributions all this stuff but
this is a highly sensitive project so
you know do we need additional steps
before we make someone a committer
or do we need to create a a greater
separation between committer and
maintainer? I think these are all topics
we need to discuss.
>> So um that means your your suggestion is
to like pause this topic for now and and
bring in your ideas about security
workflows and so on. Um before we
continue on that is is that what you
suggest Keith just for me to to
understand it?
>> Yeah. Yes. And I apologize Jesse we are
making you the guinea pigg uh in this
conversation uh and I apologize for that
but yeah I just think we need to sort
out some some of the concepts around
security for someone to become a
committer or maintainer on a sensitive
repo. Um I think yeah we just have a
responsibility to kind of talk about
that.
>> Yeah. Um
Sophie has hands up and and then I I
would like to uh say something too.
>> Yeah, we we currently have very
lightweight
guidelines on the qualifications to
become a committer, a maintainer and a
triage a junior committer. Um, I have
opened up a pull request that tries to
create some kind of pillars as
guidelines that the individual
repositories
can um add to the pillars and also
um specify the level of difficulty and
you know the volume of contributions or
the depth of contributions and things.
Um,
so I think that might complement sort of
like the conversation next week where
we've both kind of independently come to
like a similar conclusion that um the
the current um committer and maintainer
qualification
requirements
um is
a little bit maybe maybe too vague. In
the case of the Python SDK, our
problem is was was a little bit
different. So my motivation to create
this was a little bit different, but we
we overlap sort of in terms of some of
the actions. Um the issue is in the
Python SDK we we have a growing team and
the current problem that we have now is
at least in my opinion I don't want to
mislead people into thinking that they
they you know might be on track to be a
committer or might be on track to be a
maintainer if that's only my individual
maintainers opinion.
um because we don't have a list of sort
of um general qualifications, general
pillars that provide like some clear
guidance and agreement between
maintainers as a whole for the the
certain level of the repository. It's
it's hard to um get some kind of
consensus there and and create a
positive image to the rest of the
the community.
Yeah, just just found it. Too many too
many. Thanks uh Danielle for for sharing
that. Too many uh open PRs currently in
the governance repo with with all the um
with all the um like clearing up of of
the groups. But but this is the the one
you mentioned, right, where you have
like the quarification and so on. And I
think we talk about two different topics
here. Why Sophie is coming from from
quarification like uh technical
understanding and what is the skill set
and so on. Keys is coming more from a
security way saying like
um how to trust people like even the
best engineer could be could be a kind
of attacker whatever right? So we have
two different um directions we are
coming from and I think both are are
valid to to be fair. Um and I believe in
both we we can become better. Um what I
do not want um is that we have a huge
pocka based on that. now and and I agree
with Keith um there is always the the
first person right and uh for the first
person it's it's always painful um and
and I think that is fine and nobody
uh here says oh if that is not solved
tomorrow next week whatever we have a
huge problem but I I think it should not
become a huge blocker and for sure
whatever we decide on on those two
topics should not um end up in um making
external individual people not from
anywhere on the world not possible to to
contribute to to those repositories
right because if we would do that
we would not be you know like open and
vendor neutral anymore if we say like I
don't know only people from companies
within the TSC or or within in FFTDT
could could contribute then we would not
have Sophie here then we would not have
Angelina here then we would not have
Jesse here and and so on I think that is
just um something we really need to take
care on that's that's my point of view
on that topic
um so is it is it fine for everybody
that um keys presents
next week um his idea about making the
core repositories of hyro how more
secure is that is that how to phrase it
keys?
>> Yeah, I mean basically the the proposal
in a nutshell is that there's additional
security requirements for someone to
become a committer or maintainer of
those repos. I also think that the
suggestion one of the other suggestions
is that you know it's been brought up
many many times that you know we really
can't trust any committer or maintainer.
So it probably also maybe is bringing in
some new security tools to scan all PRs
looking for malicious PRs. So probably
the the two convers you know there's
it's not one thing it's probably a few
different things. The other one would be
probably creating more of a separation
between maintainer and committer. That
would allow more like quote unquote
untrusted committers, but keeping that
maintainers are highly trusted.
>> Yeah, actually I can already say GitHub
does not allow that [laughter] because
you have the right role and and that's
that's the role on on GitHub. I
understand what you say.
>> Um talking about this on the community
call with like trying to figure out what
GitHub actually lets you do. Uh yeah,
>> Ethan Hendrick where if you would
actually be able to separate them.
>> Um Jessica said that you could in theory
create a custom rule, but yeah, I I I
think that that's that's something that
we will have to look into whether like
what what is actually possible and
feasible. Um
>> yeah.
>> Well well I yeah there's there's but
there are rule I I think you can set up
rules. Let's say like if a committer
approves a PR, you need to have like two
approvals where maybe if a maintainer
approves, it's one approval. I don't
know, something like there's many
different ways to to look at this
problem.
>> Yeah. Yeah. Yeah. As as as said, so
happy for me, I I like to have more
security because I see the the benefits.
I I think it must not become a
bottleneck on time until we can onboard
new people or on on general on boarding.
And and as long as it's like that, I'm
I'm more than than happy um for for
100%. Actually, funny for for the um for
this specific case, but not that I want
to move it forward, but Sophie, Jessica,
um and me, those are the people on the
call, have already met met Jesse in
person on on the Hierro community day.
Um if if we want to put something like
that as a you know like kind kind of
must um this is something that already
has has happened and why I like to to
really bring bring this topic up here
because we know he's he's a real person
and he works on on that that stuff even
in university. But not I'm not trying to
to push him, you know, just trying to to
make sure that we already try to think
about stuff like that. Okay. So
[laughter] Jessica is power
to prove it. Yeah, I like that. Good. Um
so um I think we have a good decision
here which is um Keith will present his
thoughts on that Z topic next week.
Maybe Sophie can even talk a little bit
about um
the qualification
um of those words. Um and actually we
are at the end of an hour
which means we have two additional
topics um that will be the top two
topics um of next week. Um so as said
that was a really packed um TSC but I
believe a lot of good topics and thank
you all for for staying here the the
hour and discussing on the topics with
us and uh see you next week.
>> Thank you. See you next week.
>> Thank you. Bye
>> bye.
Bye.