Skip to content

10th Aug 2026 - GitProxy Meeting Minutes #1665

Description

@kriswest

Date

20260810 - time

Meeting info

Meeting notices

  • FINOS Project leads are responsible for observing the FINOS guidelines for running project meetings. Project maintainers can find additional resources in the FINOS Maintainers Cheatsheet.

  • All participants in FINOS project meetings are subject to the LF Antitrust Policy, the FINOS Community Code of Conduct and all other FINOS policies.

  • FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact legal@finos.org with any questions.

  • FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.

Agenda


Meeting Minutes

  • Approval of Past Meeting Minutes

  • Update Git proxy's governance to latest FINOS standard and formalise agreement reviews

  • 2.1.0 Release Status

    • 2.1.0 is ready; demo video scheduled to be recorded and release to be published imminently (@jescalada).
    • Final placement of demo video (contributing guide or repo) discussed; preferred to keep it accessible.
  • 2.2.0 Release Preparation

    • HTTP Basic and NTLM auth methods merged and moved to 2.1.0 milestone.
    • Remaining features for 2.2.0 include refreshed UI, Postgres support, modification date fields, hybrid cache architecture, LDAP improvements, and dependency upgrades.
    • Dependency upgrades (e.g., Vitest 4, TypeScript, TypeScript ESLint) should be grouped for easier maintenance.
    • Migration of E2E tests from Cypress to Playwright discussed as a future enhancement.
  • Using Git Proxy to govern other GitHub/GitLab activity such as issues, PRs, Discussions, Comments, Access to release assets, etc. (Not discussed in depth)

    • Topic deferred to future meetings. Initial ideas and requirements were raised, but a full discussion was not held due to time constraints.
  • AOB, Q&A & Adjourn

    • No further business raised; next meeting scheduled for 24th August.

Rolling Over/Comments on Previous Action Items

  • Internal security requirements (user credentials/tokens, OAuth, signing) have been completed after discussions with security teams.
  • New maintainer onboarding continues; Citi team maintainers and PRs outstanding.
  • Deprecation warning PR merged, but needs generalising to schema-based warnings; new issue to be raised (@jescalada).
  • Recruitment of new maintainers/reviewers ongoing; @kriswest working with a new contributor (Adrian Neow).
  • Combined SQL/Postgres PR is still in progress (@dcoric / @fabiovincenzi); main PR and documentation being prepared.
  • Review and feedback for SSH fingerprint verification was not clear; identified as issue SSH fingerprint verification #1648@fabiovincenzi to review and follow up.
  • LDAP PR conflicts and coverage improvements still pending (@jescalada coordinating).
  • FINOS events team follow-up for OSFF New York booth logistics not completed; needs action.
  • GitProxy Boy vulnerability review (OSTIF) ongoing; to be monitored and action item rewritten for clarity.

Action Items


Not Discussed

  • "Using Git Proxy to govern other GitHub/GitLab activity such as issues, PRs, Discussions, Comments, Access to release assets, etc."
    • Deferred due to time; added to future agenda.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions