Skip to content

27th July 2026 - GitProxy Meeting Minutes #1659

Description

@kriswest

Date

20260727 - 4pm BST / 11am EDT

Meeting info

Meeting notices

  • FINOS Project leads are responsible for observing the FINOS guidelines for running project meetings. Project maintainers can find additional resources in the FINOS Maintainers Cheatsheet.

  • All participants in FINOS project meetings are subject to the LF Antitrust Policy, the FINOS Community Code of Conduct and all other FINOS policies.

  • FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact legal@finos.org with any questions.

  • FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.

Agenda

Meeting Minutes

  • Past Meeting Minutes Approved:
    The minutes from the 13th July 2026 (13th July 2026 - GitProxy Meeting Minutes #1629) were approved without objection.

  • GitProxy Health Report:
    @jescalada presented the project health report; discussion focused on using the report to increase marketing and visibility for GitProxy. Upcoming TOC presentation was noted, and contributors were encouraged to support if available.

  • Maintainer Appointments & Governance Updates:

    • @fabiovincenzi and @dcoric maintainer appointments were confirmed pending contact email updates.
    • Discussion on whether personal or company emails should be used; consensus is that either is permitted, subject to company policy.
    • Updates to project governance to meet latest FINOS standards were agreed.
    • Deduplication of governance and contribution process documentation suggested; action raised to merge and modernise files.
  • 2.1 Release Status:

  • 2.2 Release Status:

    • Multiple PRs related to SQL/Postgres support (by @dcoric) are ready but dependent on approval/merge of the base PR.
    • Discussion around maintaining multiple database adapters and the need for contributor documentation and migration tools.
    • Interns are working on UI features; accessibility improvements to be handled after main UI PR is merged.
  • Other PRs in Need of Review:

    • NTLM/Basic Auth chunked response PR (health warning/comment) completed by @Andreybest; awaiting review and merge.
    • Deprecation warning PR (schema-based, legacy config) approved by @jescalada; ready to merge.
  • SSH Fingerprint Verification:

    • No new discussion or progress noted; item remains open.
  • AOB/Q&A:

    • Zizmor workflow vulnerability scanning PR discussed; @jescalada to raise issue for scorecard results and consider manual checks.
    • GitProxy Boy vulnerability review deferred to next meeting pending more updates.
    • LDAP PR by new contributor needs conflict resolution and further review; @jescalada will follow up.
    • Policy discussions on repository domain whitelisting and onboarding; agreed to park for now and revisit in future releases.

Action Items

  • @Andreybest: Propose slots for architecture/workflow roadmap workshop (coordinate with @grovesy and Citi participants).
  • @kriswest / @andypols: Continue to collate and document internal security requirements (user credentials/tokens, OAuth, signing).
  • @Andreybest: Submit initial PR for alternative to TSOA for API documentation/control (Nest/TSNext); review and iterate.
  • @jescalada / @andypols: Review and merge workflow fixes PR (ci: refactor workflows for release branching #1520) and package.json bumper workflow PR (ci: add package.json bumper workflow #1627); post demo video after merging.
  • @jescalada / @kriswest: Mentor and encourage new maintainers (@fabiovincenzi, @dcoric, Citi team); ensure maintainers.md PRs are submitted and emails are updated per company policy.
  • @re-vlad: Refactor deprecation warning PR to use schema-based approach for legacy config field warnings (confirm post-merge).
  • @ALL: Actively recruit additional maintainers/reviewers, especially from G-Research and Citi, to accelerate PR review.
  • @ALL: Review and address merge conflicts and outstanding review requests (including UI accessibility, event handler/notification features).
  • @jescalada: Follow up with FINOS events team for OSFF New York booth logistics and content updates.
  • @dcoric / @fabiovincenzi: Create subtasks and combine smaller SQL/Postgres PRs into a main feature PR; provide documentation and migration tools.
  • @andypols: Implement generic migration mechanism for database schema/data changes via the sync adapter interface.
  • @jescalada / @kriswest: Raise issue on Zizmor repo for scorecard results; manually run scorecard and report if needed.
  • @jescalada: Resolve conflicts and coordinate minor changes for LDAP PR; follow up with contributor for coverage improvements.
  • @ALL: Provide feedback and review for SSH fingerprint verification PR.
  • @ALL: Continue to monitor and contribute to GitProxy Boy vulnerability review as updates become available.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions