| title | Project Management |
|---|
Under the topic "project management" we describe how we do the organizational stuff besides coding such as on-/off-boarding new maintainers or contributors.
- We use GitHub for source code and issue management:
- We have an own organization named secureCodeBox.
- Management of issues is done with a corresponding project.
- We use the OWASP Google Workspace:
- A shared drive to store meeting notes.
- And a project calendar:
- We have registerded one domain (
securecodebox.io) which is sponsored by iteratec.- The DNS cone is managed via iteratec Azure Portal by the admin-team.
- The website [https://www.securecodebox.io] is hosted on Netlify.
We use these full qualified domain names:
- For our main website:
- www.securecodebox.io -> docs-securecodebox.netlify.app
The website and documentation is based on Docusaurus and hosted on Netlify. The login is documented in our vault.
DOCKER_NAMESPACE— Namespace for the Docker images. For the main repository this is securecodebox.DOCKER_USERNAME— Username used to push Docker images.DOCKER_TOKEN— Token that enables the CI to push Docker images.GPG_COMMITS_PASSPHRASE— GPG passphrase for the secureCodeBoxBot.GPG_COMMITS_PRIVATE_KEY— GPG private key for the secureCodeBoxBot.SCB_BOT_DOCU_ROULETTE_TOKEN— GitHub token for the documentation roulette (needsorg:readpermission).SCB_BOT_USER_TOKEN— GitHub token for the secureCodeBoxBot.SONAR_TOKEN— Token for SonarCloud.
In our GitHub organization we have several teams:
- admin-team: Members are the project leads.
- core-team: Company sponsored core team.
- contributor-team: Active contributors from the community.
- bot-team: Team containing all bots allowed to push directly to the main branch.
In our DockerHub organization we have several teams:
- adminteam: Members are the project leads.
- coreteam: Company sponsored core team.
- botteam: Team containing all bot accounts.
In our Sonatype organization we have the namespace "io.securecodebox" for Java Maven artifacts.
Users of this namespace are the project leads and a bot user for deployments.
We use FOSSA in the free tier option for open source projects to check our dependencies for violating licenses. It is integrated in the repository as a webhook. Individual persons log in there using GitHub after onboarding. We onboard everyone in the admin-team.
- The project leads do a regular sync meeting:
- Monday 16:05-17:00 CET, every 4 weeks from 28.5.25 on. Next meetings: 23.6.25, 21.7.25 etc.
- We write an agenda beforehand and notes in a Google Doc, one per meeting.
- There is a template document in the shared drive.
For on- and off-boarding we create an issue for each member. On- and off-boardings need to be done by a member of the admin-team.
- core-team:
- Add to our GitHub organization with following roles:
- core-team
- contributor-team
- Add to our GitHub organization with following roles:
- admin-team (additionally to the core-team on-boarding):
- Add to our GitHub organization with following roles:
- admin-team
- Register user at Sonatype & add to namespace "io.securecodebox"
- Add to OWASP valut.
- Invite to FOSSA organization with role Admin (we use the OWASP mail address because GH invite didn't work when tried).
- Add to our GitHub organization with following roles:
- core-team:
- Remove role:
- core-team
- Remove role:
- admin-team:
- Remove role:
- admin-team
- Remove user from namespace "io.securecodebox" in SonaType.
- Remove access to OWASP vault.
- Remove from FOSSA organization
- Remove role: