Skip to content

RFC 0036: Update ODP Private Repository Access Control - #48

Open
makubacki wants to merge 1 commit into
OpenDevicePartnership:mainfrom
makubacki:rfc_0036_rev_private_repos_allowed
Open

RFC 0036: Update ODP Private Repository Access Control#48
makubacki wants to merge 1 commit into
OpenDevicePartnership:mainfrom
makubacki:rfc_0036_rev_private_repos_allowed

Conversation

@makubacki

@makubacki makubacki commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Updates the RFC to more generally cover private repository policy in
the OpenDevicePartnership GitHub organization.

Adds a requirement that private repositories are only for staging
content to go public and should not contain any confidential content
or material with no public plan. Simplifies requirements and overall
policy accordingly while still retaining GitHub teams to manage and
audit private repository access on a per-repository basis. Overall,
reduces administrative overhead for managing private repositories.

@makubacki
makubacki requested a review from a team as a code owner August 4, 2026 00:03
Copilot AI review requested due to automatic review settings August 4, 2026 00:03
@makubacki makubacki self-assigned this Aug 4, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates RFC 0036 to broaden the policy from “default private repo access behavior” into a more general statement about the intended role of private repositories in the OpenDevicePartnership (ODP) GitHub organization—positioning private repos as temporary staging for content intended to become public, and explicitly excluding confidential/no-public-plan work from the org.

Changes:

  • Reframes the RFC motivation/goals around organizational openness while constraining when private repos are appropriate.
  • Simplifies and updates the normative requirements and guidance (including adoption/transition checklist).
  • Updates the Alternatives section to align with the revised private-repo role.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread rfc/0036-private-repo-access-control.md Outdated
Comment thread rfc/0036-private-repo-access-control.md Outdated
Comment thread rfc/0036-private-repo-access-control.md Outdated
Comment thread rfc/0036-private-repo-access-control.md Outdated
@makubacki
makubacki force-pushed the rfc_0036_rev_private_repos_allowed branch from 101344f to 096e0ea Compare August 4, 2026 00:32
Updates the RFC to more generally cover private repository policy in
the OpenDevicePartnership GitHub organization.

Adds a requirement that private repositories are only for staging
content to go public and should not contain any confidential content
or material with no public plan. Simplifies requirements and overall
policy accordingly while still retaining GitHub teams to manage and
audit private repository access on a per-repository basis. Overall,
reduces administrative overhead for managing private repositories.

Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
@makubacki
makubacki force-pushed the rfc_0036_rev_private_repos_allowed branch from 096e0ea to dcb6917 Compare August 4, 2026 16:46
@jerrysxie
jerrysxie requested a review from a team August 4, 2026 20:17
Comment thread rfc/0036-private-repo-access-control.md
makubacki added a commit that referenced this pull request Aug 5, 2026
Adds a topic for the PR #48 to the agenda.

Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants