Hi,
Some of you probably already noticed it and I will continue this work soon: I'm reducing permissions of some people that are:
- either not participating actively to the project anymore - they are still part of the org as we have an alumni group
- or don't really do tasks that are requiring the elevated permissions they have - at least not to our knowledge
Note that this has nothing to do with not trusting people and has all to do with reducing our supply chain attack exposure by reducing the number of accounts with elevated privileges.
If you get an email from GitHub and you think something has gone wrong, please contact me privately so that we can discuss the situation.
Thanks.
--
Guillaume