Skip to content

Commit 3e9a565

Browse files
committed
meta: discuss authenticity of nominees
1 parent 9a1d862 commit 3e9a565

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

GOVERNANCE.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -263,6 +263,20 @@ push commits, etc.), so what's the minimal amount is subjective, and there will
263263
be cases where collaborators disagree on whether a nomination should move
264264
forward.
265265

266+
#### The Authenticity of Contributors
267+
268+
The Node.js project does not require that contributors use their legal names or
269+
provide any personal information verifying their identity.
270+
271+
It is not uncommon for malicious actors to attempt to gain commit access to
272+
open-source projects in order to inject malicious code or for other nefarious
273+
purposes. The Node.js project has a number of mechanisms in place to prevent
274+
this, but it is important to be vigilant. If you have concerns about the
275+
authenticity of a contributor, please raise them with the TSC. Anyone nominating
276+
a new collaborator should take reasonable steps to verify that the contributions
277+
of the nominee are authentic and made in good faith. This is not always easy,
278+
but it is important.
279+
266280
### Onboarding
267281

268282
After the nomination passes, a TSC member onboards the new collaborator. See

0 commit comments

Comments
 (0)