Skip to content

13th July 2026 - GitProxy Meeting Minutes #1629

Description

@kriswest

Date

20260713 - 4pm BST / 11am EDT

Meeting info

Meeting notices

  • FINOS Project leads are responsible for observing the FINOS guidelines for running project meetings. Project maintainers can find additional resources in the FINOS Maintainers Cheatsheet.

  • All participants in FINOS project meetings are subject to the LF Antitrust Policy, the FINOS Community Code of Conduct and all other FINOS policies.

  • FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact legal@finos.org with any questions.

  • FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.

Agenda

Meeting Minutes

Meeting Minutes

  • New Participants Introduced

    • Morgan Thomas (work experience via Rob Moffat) introduced himself.
    • Kaitlynn and the group of NatWest interns introduced themselves as part of the summer OSPO team.
  • Approval of Previous Meeting Minutes

  • Previous Action Items

    • Several items were marked as complete, including automation of version bumping workflow, reassignment and relabelling of issues, and PR reviews.
    • The architecture/workflow roadmap workshop is still pending. @Andreybest volunteered to contact @grovesy to clarify next steps.
    • Internal security requirements for storing credentials need further input; @kriswest and @andypols to coordinate.
    • Incorporation of Agentic workflow feedback is deferred to a future meeting.
    • All are encouraged to actively propose topics for next meetings and resolve any merge conflicts as assigned.
  • 2.1 Milestone PRs

    • feat: add tsoa for API type control and documentation #1501:
      • Discussion centred on the now-unmaintained TSOA library. Several alternatives (TS REST, NestJS, Adonis.js) were discussed, with a preference for a well-maintained solution.
      • Decision: De-scope this PR from 2.1; @Andreybest will attempt a new approach based on group discussion.
    • ci: refactor workflows for release branching #1520:
      • Marked as complete. @jescalada to produce a demo video of the release workflow for documentation.
    • feat(upstream-proxy): add HTTP Basic and NTLM auth methods #1551:
      • Identified edge cases with chunked 407 responses. Most environments unaffected, but a health warning and code comment are to be added. May move to 2.2 if not completed for 2.1.
  • Contribution Speed Issues

    • Broad agreement that review/merge speed is a bottleneck, primarily due to limited reviewers and a policy requiring reviews from other firms.
    • Discussed relaxing the policy to allow reviews from maintainers within the same firm, provided it is not self-approval.
    • Plan to appoint more maintainers, especially from @jescalada/@kriswest (@G-Research, @Citi) teams.
    • Consensus to pursue more frequent, smaller releases rather than holding work for milestones.
  • Fogwall Feature Porting PRs

    • Live feedback during pushes, error collection, and disconnect detection features were reviewed:
      • feat: add live feedback during pushes (sideband streaming) #1637: Approved pending auto-merge after checks.
      • feat: execute all steps and collect errors at end of chain #1640: Feedback to remove config setting and possibly allow plugins to self-declare error behaviour. To be updated and re-approved.
      • feat: implement disconnect detection, cancel pushes on disconnect #1641: Explanation provided; still in draft. Testing challenges noted. Will remain draft while further experimentation occurs.
    • Plug-in architecture needs to be extended to support UI notifications/advisories, not just action lists.
  • GitProxy Health Report + TOC Presentation

    • @jescalada preparing for TOC presentation (technical-oversight-committee#299). @kriswest to review the document. Encouraged to highlight active contribution and project relevance.
    • @jescalada will present; other maintainers welcome but not required.
  • Deprecation Warnings for Legacy Config Fields

    • feat(config): add deprecation warnings for legacy config fields (Phase 1: warnings in 2.x) #1626:
      • Proposal to warn users in 2.x, with breaking changes in 3.x.
      • Feedback given to pull deprecation info from config schema, using descriptions for replacement suggestions.
  • OSFF New York (November) GitProxy Booth

    • @jescalada plans to staff the booth and is considering submitting a talk.
    • Encouragement provided to submit a session talk, with reassurance about the supportive conference environment.
    • Discussion on content and flyer updates; @jescalada to coordinate with FINOS events lead (Eteri).
  • AOB / Q&A

    • Discussion on blog/article tone for upcoming GitProxy communications—should balance technical/corporate messaging for both OSPO and developer audiences.
    • Noted need to review and merge the event notification/handler PRs, particularly for email notification support.
  • Not Discussed

    • No items skipped; all agenda topics were addressed, though some (like Agentic workflows) were deferred for future meetings.
    • No substantial open Q&A/AOB topics, beyond blog/article and booth planning.

Action Items

  • @grovesy / @Andreybest: Update and clarify next steps for architecture/workflow roadmap workshop. Coordinate schedule and scope.
  • @kriswest / @andypols: Collate and document internal security requirements for user credentials/tokens handling, including encryption at rest.
  • @kriswest: Review and provide feedback on GitProxy Health Report PR for TOC (technical-oversight-committee#299).
  • @Andreybest: Attempt an alternative to TSOA for API type control/documentation; propose library in issue and migrate as agreed.
  • @jescalada: Record and post a video demonstration of the new automated release workflow (2.1 bump).
  • @Andreybest: Add health warning and explanatory comment for NTLM/Basic auth chunked response edge case; defer to 2.2 if not resolved for 2.1.
  • @jescalada / @kriswest / @andypols / @re-vlad: Review and merge Fogwall feature porting PRs as updated, especially feat: add live feedback during pushes (sideband streaming) #1637, feat: execute all steps and collect errors at end of chain #1640, feat: implement disconnect detection, cancel pushes on disconnect #1641.
  • @jescalada / @kriswest: Encourage and mentor new maintainers from G-Research and Citi; submit maintainers.md PRs as appropriate.
  • @re-vlad: Refactor deprecation warning PR to use schema-based approach for legacy config field warnings.
  • @ALL: Actively recruit more maintainers/reviewers to speed up PR review and merging.
  • @ALL: Review and address merge conflicts and outstanding review requests, including event handler/notification features.
  • @jescalada: Coordinate OSFF New York booth logistics and content updates with FINOS events team.
  • @jescalada: Update the "execute all steps and collect errors" PR to remove the config setting and add support for plugins to self-declare their behavior.
  • @jescalada: Submit (optionally) a talk proposal for OSFF New York GitProxy session; seek peer review/support if needed.
  • @jescalada: Share published GitProxy blog on mailing list upon release to maximise project awareness.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions