node/doc/contributing/security-steward-on-off-boarding.md
Michael Dawson 1cf74beb57
doc: make contributing info more discoverable
There are been several discussions in recent PRs about
the docs related to contributing not being very discoverable.
Move these docs from doc/guides/ to doc/contributing.

Signed-off-by: Michael Dawson <mdawson@devrus.com>

PR-URL: https://github.com/nodejs/node/pull/41408
Reviewed-By: Franziska Hinkelmann <franziska.hinkelmann@gmail.com>
Reviewed-By: Michaël Zasso <targos@protonmail.com>
Reviewed-By: Derek Lewis <DerekNonGeneric@inf.is>
Reviewed-By: Mary Marchini <oss@mmarchini.me>
Reviewed-By: James M Snell <jasnell@gmail.com>
2022-03-14 09:31:08 -04:00

914 B

Security Steward Onboarding/OffBoarding

Onboarding

  • Confirm the new steward agrees to keep all private information confidential to the project and not to use/disclose to their employer.
  • Add them to the security-stewards team in the GitHub nodejs-private organization.
  • Ensure they have 2FA enabled in H1.
  • Add them to the standard team in H1 using this page.
  • Add them as managers of the nodejs-sec mailing list.

Offboarding

  • Remove them from security-stewards team in the GitHub nodejs-private organization.
  • Unless they have access for another reason, remove them from the standard team in H1 using this page.
  • Downgrade their account to regular member in the nodejs-sec mailing list.