Skip to content

docs: say who qualifies for private repository access - #23

Merged
aljo242 merged 4 commits into
mainfrom
docs/who-qualifies-for-access
Oct 2, 2026
Merged

aljo242 merged 4 commits into
mainfrom
docs/who-qualifies-for-access

Conversation

@aljo242

@aljo242 aljo242 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

"Downstream teams that have passed KYC" never said whether an exchange running the software qualifies, while the distribution rule says not to pass patch source to validators or node operators. A professional operator was on the wrong side of one of those.

Chain development teams and major exchange partners qualify, through KYC and directly from us. The redistribution rule is unchanged.

"Downstream teams" did not settle whether an exchange running the software
qualifies, and the policy tells teams not to pass patch source to validators or
node operators, so a professional operator read both halves and found itself on
the wrong side of one of them.

Chain development teams and major exchange partners qualify, through KYC and
directly from us. The restriction on passing source on is unchanged, because it
governs redistribution rather than who can be granted access.

Raised by Eric reviewing the security blog draft.
@aljo242
aljo242 requested a review from a team as a code owner October 2, 2026 16:50
@greptile-apps

greptile-apps Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[Low risk] Updates security policy documentation for private repository access.

The access-policy wording should be clarified before merging so both recipient groups are explicitly subject to KYC and production-use requirements.

Findings

  1. P1 Access requirements may not apply ▶

Summary

The PR replaces the general “downstream teams” access category with chain development teams and major exchange partners. The new sentence does not clearly apply the existing KYC and production-use prerequisites to both groups.

Reviews (1) · Last reviewed commit: "docs: say who qualifies for private repo..."

Comment thread SECURITY.md Outdated
Comment on lines +99 to +100
Access is granted to chain development teams and to major exchange partners that
have passed KYC and run the repository in production. Each month's repositories

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Access requirements may not apply

The phrase “that have passed KYC and run the repository in production” follows only “major exchange partners.” An administrator could read this as granting chain development teams access without either requirement, allowing invitations to private patch repositories without the previously required KYC check. Make clear that both groups must meet both requirements.

Suggested change
Access is granted to chain development teams and to major exchange partners that
have passed KYC and run the repository in production. Each month's repositories
Access is granted to chain development teams and major exchange partners only if
each team has passed KYC and runs the repository in production. Each month's repositories

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

The relative clause attached only to the second group, so the sentence could be
read as granting chain development teams access without KYC or a production
deployment.
@aljo242
aljo242 merged commit 54a505b into main Oct 2, 2026
1 check passed
@aljo242
aljo242 deleted the docs/who-qualifies-for-access branch October 2, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant