Closed (fixed)
Project:
Drupal Community Governance
Component:
Policies
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
17 Sep 2024 at 02:16 UTC
Updated:
17 Mar 2026 at 22:00 UTC
Jump to comment: Most recent
Document decisions made about TUF in core issues
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
quietone commentedThis should also include #3331078: Add php-tuf/composer-stager to core dependencies — for experimental Automatic Updates & Project Browser modules
Comment #4
cmlaraMy understanding is the D.O. Ecosystem wants PHP-TUF to be adopted by other providers correct? Sites like packagist.org and really every composer repository out there?
If that is a fair statement I would suggest a radially different policy compared to what is currently proposed:
Separate the TUF projects from Drupal core.
Do not allow core maintainer status to play any role in the TUF project management, give the project an initial developer team and let them choose how the project is run, who is a maintainer, and have sole authority independent of the desires of the Drupal Core project or the Drupal.org infrastructure team.
Give the TUF project the freedom to make decisions that Drupal would disagree with in order to promote the protocols growth. Allow it to become its own ecosystem, do not try and force control over it from one single project that represents a fraction of the global Composer usage.
Comment #5
hestenetThe language provides space for governance adjustments if projects like PHP-TUF *do* get that wider adoption, so I personally feel this first iteration is ready to go.
Comment #7
poker10 commentedThe main heading is "Governance of php-tuf/composer-integration and php-tuf/php-tuf", but the text later mentions "all three" and "php-tuf/php-tuf, php-tuf/composer-stager, and `composer-integration'". Do we need to update the main title to include all three projects?
Also added some minor style fix to the MR.
Comment #8
quietone commentedThis has been an item in the package manager meeting on Slack in October and December and now, in January. I think there have been ample opportunity for everyone to respond. So, lets commit this so we can use it in further discussions.
Comment #9
hestenetIf no further comment, let's commit 1 week from today.
Comment #11
hestenet