tag-security
tag-security copied to clipboard
[Suggestion] Approval process for PRs of a WG
Description: As part of the Compliance WG we want to add and manage content within our Compliance folder community/working-groups/compliance in the TAG-Security github repo. Since every time a content is added/updated we need to create a PR and a Tag-security maintainer needs to approve/merge it. If the WG content is updated frequently it will require involvement of the TAG-Security maintainer to approve it every time.
One option we discussed in the Compliance WG call last time was to see if it is possible to have folder level approval process. I believe using CODEOWNERS file we can allow approvers for specific folder in the Tag-security github repo. Will it be possible to use this option to add 2-3 approvers for compliance folder so that we don't need to bother the TAG-Security maintainers every time we need to update the content?
The other option is to follow the current process of TAG-Security maintainer approving every PR for content update within Compliance WG folder.
Would like to understand which option works best for the TAG or if there is any other alternative.