Path: csiph.com!eternal-september.org!feeder.eternal-september.org!news.szaf.org!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod From: Craig Small Newsgroups: linux.debian.maint.python Subject: Re: Thoughts on removing access to the Python teams repositories to inactive members ? Date: Mon, 12 Jan 2026 22:40:01 +0100 Message-ID: References: X-Original-To: =?UTF-8?Q?Louis=2DPhilippe_V=C3=A9ronneau?= X-Mailbox-Line: From debian-python-request@lists.debian.org Mon Jan 12 21:36:48 2026 Old-Return-Path: X-Amavis-Spam-Status: No, score=-105.209 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=2, LDO_WHITELIST=-5, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, USER_IN_DKIM_WELCOMELIST=-0.01, USER_IN_DKIM_WHITELIST=-100] autolearn=no autolearn_force=no X-Policyd-Weight: using cached result; rate: -3.5 X-Greylist: delayed 600 seconds by postgrey-1.36 at bendel; Mon, 12 Jan 2026 21:36:33 UTC X-Gm-Message-State: AOJu0Yy43idX/KxrilGfcGT17fQkbZQjfpjyt8bzzfXmbPWWjNrQjEjm SaGZbhjMb3zwB4PIJbz3dQR9rwLipdBNGgaME4+FZJAUqnimRtDZg262SYelVl1RwS7r+K8pQXS vpt7deagvShdRMicGrxMLSlrbr01EdMyyRZlxgv0U6g== X-Google-SMTP-Source: AGHT+IG1enZV0k8UOC9lGv3t5cnXFsyrln5So7kaa47pij9H3+5bt7zqi4z2zPF1bh4duGhYCvOclXQrPMtOd563GG8= X-Received: by 2002:a05:6102:3ecd:b0:5e5:6360:1f60 with SMTP id ada2fe7eead31-5ecbb1423bfmr8296112137.41.1768253161312; Mon, 12 Jan 2026 13:26:01 -0800 (PST) MIME-Version: 1.0 X-Gmail-Original-Message-ID: X-Gm-Features: AZwV_Qh8vcNGHB-sr-_Po_lveDdSjlK50CGVgtCM3ek7BqnkNDm1xcWB-YPHt2g Content-Type: multipart/alternative; boundary="0000000000008dad69064837857c" X-Mailing-List: archive/latest/23595 List-ID: List-URL: List-Archive: https://lists.debian.org/msgid-search/CALy8Cw7xAPxiTAHyxHhqB64ZkhxAKBAr1btzK+n6=09q8CmfzA@mail.gmail.com Approved: robomod@news.nic.it Lines: 76 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Cc: debian-python X-Original-Date: Tue, 13 Jan 2026 08:25:50 +1100 X-Original-Message-ID: X-Original-References: <4370652.mvXUDI8C0e@soren-desktop> <87344ay385.fsf@fama.lan> <209455ba-a05e-40b6-90af-bf939f741724@debian.org> Xref: csiph.com linux.debian.maint.python:17345 --0000000000008dad69064837857c Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi, I think this idea is good security hygiene. A 3+ years list would help in a way because it can bring up corner cases or problems wirh the filtering method, such as: On Tue, 13 Jan 2026, 8:06=E2=80=AFam Louis-Philippe V=C3=A9ronneau, wrote: > > 1. It's inactivity _in the Debian Python team_ only. That doesn't mean > these people aren't active members of the Debian community :) > > 2. That info is already public: > > https://salsa.debian.org/groups/python-team/packages/-/group_members?sort= =3Doldest_last_activity The first item doesn't match the second there. If the intent is to remove people from the Python team due to not doing anything with the Python team for (say) 3 years you'll need to look for that info elsewhere. That list is sorted by any salsa activity. For example it says my last activity was 6 Jan 2026, which it was for the Debian project. My last Python activity was February 2025. Now on that list for 3+ years means they've done nothing on Salsa anywhere so definitely they've not done anything in the Python project, so its a good start but won't meet the full goal. - Craig --0000000000008dad69064837857c Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hi,
=C2=A0 I think this idea = is good security hygiene. A 3+ years list would help in a way because it ca= n bring up corner cases or problems wirh the filtering method, such as:
=
On Tue, 13 Jan 2026, 8:06=E2=80=AFam Louis-Ph= ilippe V=C3=A9ronneau, <pollo@debian= .org> wrote:

1. It's inactivity _in the Debian Python team_ only. That doesn't m= ean
these people aren't active members of the Debian community :)

2. That info is already public:
https://salsa.debian.org/groups/python-team/packages/-/group_members= ?sort=3Doldest_last_activity
=
The first item doesn't match the second the= re.

If the intent is to = remove people from the Python team due to not doing anything with the Pytho= n team for (say) 3 years you'll need to look for that info elsewhere.

That list is sorted by an= y salsa activity.=C2=A0 For example it says my last activity was 6 Jan 2026= , which it was for the Debian project.

My last Python activity was February 2025.

Now=C2=A0 on that list for 3+ years means= they've done nothing on Salsa anywhere so definitely they've not d= one anything in the Python project, so its a good start but won't meet = the full goal.

=C2=A0- C= raig

--0000000000008dad69064837857c--