VOTE: hardware 2FA for project sensitive access
by Marc Jeanmougin
Dear leadership committee,
Your attention is required to vote on the following matters:
Background:
Some contributors have, or need to have, access to social media accounts
to post on the behalf of the project, or to infrastructure accounts,
most importantly gitlab. For computer security, we would like to protect
those accesses with a safe 2FA method, and the safest method to avoid
impersonation and phishing attacks is a 2FA hardware token with FIDO2 or
U2F. Then we would be able to set a policy to enforce 2fa when
contributors need access to passwords that would be shared on nextcloud,
or to contributors with "owner" access to gitlab projects.
The most common such token is the Yubikey (45€/$ a piece+10
tax+5shipping) but there are equivalents with open hardware component
and open source software (e.g. solokeys at 35€/$ incl. tax +5€ shipping,
or nitrokey ). As for the amount of people, the vectors team has around
10-15 people with some level of access to passwords of the project, 4
people do not have 2FA and have "owner" access to the whole gitlab
project, + 2 "maintainer" access to inkscape/inkscape (and more in other
sub-projects). We also have the possibility to offer it to all regular
contributors for whom it would be useful.
It is yet to be seen whether we could have a discount by asking, or if
there is a way to pay for the whole order and get a single reimbursement
instead of reimbursing individual contributors
Ballot:
a. Reimburse up to 2000 USD for password and project protection, and
also offering it to contributors who have been in the project for more
than a year and ask for it (implies support for option b)
b. Reimburse up to 1000 USD to protect the project's passwords on
nextcloud and gitlab project access (only contributors who have access
to nextcloud, and gitlab maintainer or owner access)
c. Do not do it
d. Other (please specify)
Thanks!
--
Marc
1 year, 2 months
VOTE: budget for mentors
by Marc Jeanmougin
Dear leadership committee,
Your attention is required to vote on the following matters:
Background:
Every year, we participate in GSoC, sometimes Outreachy, with a few
community members mentoring new contributors. This mentoring task takes
time and efforts, and offering support for potential mentors may help
them dedicate more time to it, and may help in the long run to have a
more diverse pool of mentors. In addition, the project gets a "project
stipend" from Google of 500$, so I'm suggesting to take from this amount
with 20% still for the project general funds.
Ballot:
a. Offer people who mentor students the possibility to ask for a stipend
of up to 400$ for the 2022 mentoring season
b. Do not do it
c. Other (please specify)
Thanks!
--
Marc
1 year, 4 months
Hiring Delays II
by Martin Owens
Dear All,
We had our video meeting today with Pono, Tav, and others. Pono has
told us that the process for hiring has to be delayed again because of
some SFC internal issues and some back and forth between some of the
Russian applicans for the job posting.
The request is that we move the schedule out by another two weeks. (for
a total of four weeks from our original timeline). Are there any
objections to pushing out the process another few weeks?
Best Regards, Martin Owens
1 year, 5 months
Inkscape 1.1.2 and Inkscape 1.2-alpha released
by Marc Jeanmougin
Inkscape 1.1.2
==============
Inkscape 1.1.2 is now released.
You can download it at:
https://inkscape.org/release/inkscape-1.1.2/
then, if you want to support Inkscape, donate to the project at:
https://inkscape.org/support-us/
----------------
Inkscape 1.1.2 is mainly a stability and bugfix release.
It fixes numerous crashes and several major inconveniences, such as lost styling
when when converting text to path, or relative position of clones pasted into
a new document
----------------
In addition, we are releasing an alpha version of Inkscape 1.2, to facilitate
testing of major upcoming features, such as the multipage support, editable
markers, on-canvas alignment, revamped alignment and snapping options, layer
and objects dialog, etc. If you find any issue with this new version, please
report it tohttps://inkscape.org/report
You can download it at
https://inkscape.org/release/1.2alpha0/
-----------------------------
Join an Inkscape project team
-----------------------------
Inkscape is always happy to welcome new contributors in various areas:
code, docs, translation, UX, bug triaging, or even outreach!
The main ways to get involved are listed onhttps://inkscape.org/contribute/
and you can get in touch with us onhttps://chat.inkscape.org/
Thanks to everyone involved in this release!
-- The Inkscape team
1 year, 5 months