Skip to content

24th August 2026 - GitProxy Meeting Minutes #1672

Description

@kriswest

Date

20260824 - 4pm BST / 11am EST

Meeting info

Meeting notices

  • FINOS Project leads are responsible for observing the FINOS guidelines for running project meetings. Project maintainers can find additional resources in the FINOS Maintainers Cheatsheet.

  • All participants in FINOS project meetings are subject to the LF Antitrust Policy, the FINOS Community Code of Conduct and all other FINOS policies.

  • FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact legal@finos.org with any questions.

  • FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.

Agenda

Meeting Minutes

  • Approve past meeting minutes:
    The minutes from 10th Aug 2026 (10th Aug 2026 - GitProxy Meeting Minutes #1665) were discussed, action items reviewed and minutes approved.

  • docs: add Technical Charter and restructure governance documentation (docs: add Technical Charter and restructure governance documentation #1664):

    • Governance and Technical Charter PR discussed; one last small edit from @coopernetes suggested and accepted (re: Docker image as supported output).
    • Awaiting final approving reviews from G-Research and Citi maintainers.
    • @Andreybest to nudge @grovesy/Paul for Citi sign-off; @jescalada to ensure G-Research review.
  • Releases: 2.1 and 2.2:

    • v2.1.0 is released.
    • Progress on v2.2.0 is strong; major features (UI refresh, DB migrations) merged.
    • Hybrid cache architecture and some Postgres work deferred to v2.3.
    • Release process is now documented (guide with screenshots, published by @jescalada).
  • Take a look at https://pre-commit.com/:

    • Discussion on leveraging pre-commit for standardising and reusing language-specific scanning hooks.
    • Agreed to explore reusing or contributing pre-commit-compatible hooks and/or push processes to improve developer and contributor workflow.
    • Action: If maintainers have time, review pre-commit.com landscape for possible integration or code reuse.
  • Consider partnering with OpenSSF to grow Git Proxy uptake and contribution:

    • Agreed to reach out via Andy Block (Red Hat) to OpenSSF for possible collaboration/visibility.
    • @kriswest to co-ordinate with FINOS and Andy Block for introductions.
  • New Issue Discussions

  • Using Git Proxy to govern other GitHub/GitLab activity:

    • Deferred to the follow-up/roadmap workshop (Wednesday session).
  • AOB, Q&A & Adjourn:

    • @andypols requested SSL support in the UI be tested by a team using the feature. No volunteers at present; will wait for feedback from broader user base.
    • Plan to raise issues for accessibility, training flows, and policy enforcement based on recent intern projects.

Action Items

  • @Andreybest: Submit initial PR for alternative to TSOA for API documentation/control (TS REST); review and iterate.
  • @ALL: Actively recruit additional maintainers/reviewers, especially from G-Research and Citi, to accelerate PR review.
  • @jescalada: Follow up with FINOS events team for OSFF New York booth logistics and content updates; CC @kriswest on last email to Eteri.
  • @ALL: Continue to monitor and contribute to OSTIF vulnerability review as updates become available; clarify and rewrite action item. (@jescalada to follow up as needed.)
  • @jescalada: Raise issue and review changes in PR feat(proxy): resolve push identity from token via SCM provider API #1604 (push identity); ensure architecture documentation is updated and maintainers understand edge cases.
  • @ALL: Review and approve governance update PR docs: add Technical Charter and restructure governance documentation #1664; request input from other maintainers (@coopernetes, @grovesy).
  • @ALL: Prepare for discussion on using Git Proxy to govern wider GitHub/GitLab activity at the next meeting; consider requirements and potential approaches.
  • @kriswest: Follow up with FINOS and Andy Block (Red Hat) for OpenSSF/OSSF partnership opportunity.
  • @ALL: Review pre-commit.com for possible hook/process reuse or integration.
  • @ALL: Volunteers needed to test SSL support in the UI (see @andypols request).
  • @dcoric: Finalise Postgres main feature PR and related sub-PR merges.
  • @fabiovincenzi / @dcoric: Review and refactor duplicated diff/log storage; ensure no breaking change for old pushes.
  • @andypols: Review and resolve possible issues/clashes with push identity and UI changes; provide update at next meeting.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions