Repository navigation
26th August 2026 - GitProxy Roadmap meeting Minutes #1702
Copy link
Copy link
Closed
Labels
Description
Activity
NatWest Git Proxy Roadmap notes
- New UI Accessibility review and remediation
- Event-hooks - Notifications
- Teams support (can't do easily here through web hooks...)
- Email Notifications
- Making sure all necessary fields are avialable in events to create good Notifications - existing PR had 2 of 8 fields we needed for a review notification card
- Better account creation/onboarding support - admins should be able to create users and assign roles before login
- Training requirements and admin approval (Contribution policy requirements)
- Checks on user when raising a push - expose to reviewer/admins
- Event hook for plugin support as well as or instead of configurable requirement.
- Push annotations - attach notes to pushes as metadata (through UI/custom push annotations handling)
- Will act as a base for raising PRs in future
- Governing other activity on GitHub (etc.) through Git Proxy
- Support for creating issues, comments, pull requests
- Auditable logs for those activities
- Optional review processes for them
- Project onboarding
- Handling requests for projects to be added to Git Proxy
- Automating as much of the onboarding process as possible, with appropriate and configurable checks or review steps.
- Plugin support?
- Potentially allow a first pull and then push review to be created before an admin needs to be involved
- Challenge is governing ingress - make it observable, governable etc. Include health warnings about ingress
G-Research Roadmap priorities:
- Postgres support
- Extending the plugin system
- Not as useful as they could be
- First PR raised to enable plugin into phases
- Mature pull request processing and extend plugins to pulls
- POC for a supply chain scanning plugin
- Security hardening
- Achieve and maintain 0 CVEs
- Resolve any OSTIF report outcomes
- Resolve AI discovered flaws
Citi
- Appoint more maintainers
- Finish creating an event-hook system and extend plugin system to support non-chain plugins
- Evolve the event hook system and ensure that event handling doesn't affect subsequent events?
- Check packages and CVEs - achieve 0 CVEs and maintain that
- Better TLS support - want OpenShift to hand-off to the container
If testing shows this doesn't work:
4. Including HTML/JS etc. from the npm module - should be possible, but need to test - particularly need to test 2.2.0 releaseQube
- Finish building out the events system
- Slack notifications
- Email notifications
- Plugin-style approach to using it
- Extend Git Proxy to cover more of the opensource lifecycle
- Raise issues and comments
- Raise PRs - pre-approve PR content
- Better handling for subsequent pushes - branch intelligence, close the old review /replace it with the new push based on which branch was being pushed.
- Sync your fork
- We use organisation-owned forks that need to be synced against the upstream repo periodically
- We have a bot that creates a fork of the project using a custom git-proxy API
- Elevate forking to a git-proxy feature?
- Reduce how much our fork diverges from main - more types of plugin support
- Finish building out the events system
Control Plane
- Check packages and CVEs - achieve 0 CVEs and maintain that
- Will help improve adoption
- Plugin support (interesting but not important for us)
- Performance measurement / enhance if needed
- Other applications for git-proxy
- Using it to apply rule to many mirrored repos
- Check packages and CVEs - achieve 0 CVEs and maintain that
Posted a consolidated summary of the roadmap discussion above
Date
20260826 - 4pm BST / 11am EDT
Meeting info
Meeting notices
FINOS Project leads are responsible for observing the FINOS guidelines for running project meetings. Project maintainers can find additional resources in the FINOS Maintainers Cheatsheet.
All participants in FINOS project meetings are subject to the LF Antitrust Policy, the FINOS Community Code of Conduct and all other FINOS policies.
FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact legal@finos.org with any questions.
FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.
Agenda
Git Proxy Project – Consolidated Roadmap Summary
This document consolidates the key roadmap priorities shared by all participating firms at the recent meeting, together with relevant GitHub comments and discussions. Items marked as high-priority have broad and/or repeated support across multiple firms and should be considered for early focus in the next phase. Other items are proposed by one or more firms and may warrant further discussion on value and sequencing - i.e. the numbering below does not provide a relative priority - that still needs to be established.
Key Roadmap Items
1. Event Hook and Notification System (High Priority)
2. Plugin System Extensions and Refactor (High Priority)
3. Supply Chain Security and Dependencies (High Priority)
4. UI Improvements and Accessibility
5. Extended Open Source Lifecycle Governance
6. Account and Project Onboarding Improvements
7. Database and Deployment Support
8. Performance and Scalability
9. Project Maintenance and Governance
Suggested Action Items
Action List for Next Community Meeting
Community members are encouraged to edit this issue to add further detail, clarify requirements, or raise new items for consideration.