Dashboard › publish › Distillation
d733f401-f871-4114-9ba7-d4ef356e9709["lore_tm_v1_Zu2NO2tdC3CKvebz3sscD1dc8ld7pPHlN7QxB2RvacY","lore_tm_v1_E_uk38X0CbWCUB9eIRw5TZKB3RZ-qvrUKKz88_LoPpc","lore_tm_v1_3bxbzAcUz8SjkYpJM6wUVzdnQevNQHYp4iCAOtcSxQs","lore_tm_v1_Z4d6BHQy1J_PNIqYr7Y1S6gA6QG_-Nv-s6KKCaZK9ck","lore_tm_v1_Tng4guxTbsYjINXBs97h63Cs7F7YzM5OiAL5Wa78L7k","lore_tm_v1__85uI4AqAwvvSNpe2COajOXr0PszEo-uCb65OsqdVJ0","lore_tm_v1_nr5u6vIDnzYE_JTZ_dLnilwWgSk7h0UvRqB0T2cnW3E","lore_tm_v1_eqHTB1V9DZ_cjHp-spKnVwI-6h_y9fx_9_ZC-xbw55Q","lore_tm_v1_VjbvyYZRLJZdGwDhh48nlnsDS6xjgdqAX-UlCvj8Rts"]
Date: Aug 27, 2026
/home/byk/Code/getsentry/security-as-code/rbac/env/prod-github/README.md states GitHub teams/members are managed in rbac/env/prod-github/team/, repository access in rbac/env/prod-github/repo, and member syncing in rbac/env/prod-github/team-members-syncing; it links Notion instructions for managing GitHub teams/members, repository access, and maintainer technical details./home/byk/Code/getsentry/publish/auto-approve-repos.txt contains 46 auto-approve repository paths, in order: 1. getsentry/arroyo; 2. getsentry/auto-type-annotate; 3. getsentry/devenv; 4. getsentry/infra-event-notifier; 5. getsentry/jest-sentry-environment; 6. getsentry/json-schema-diff; 7. getsentry/js-source-scopes; 8. getsentry/objectstore/clients; 9. getsentry/ophio; 10. getsentry/pdb; 11. getsentry/pyo3-python-tracing-subscriber; 12. getsentry/pytest-sentry; 13. getsentry/relay/py; 14. getsentry/responses; 15. getsentry/rust-proguard; 16. getsentry/rust-sourcemap; 17. getsentry/rust-usage-accountant; 18. getsentry/script-runner; 19. getsentry/sentry-api-schema; 20. getsentry/sentry-forked-djangorestframework-stubs; 21. getsentry/sentry-forked-django-stubs; 22. getsentry/sentry-forked-jsonnet; 23. getsentry/sentry-infra-tools; 24. getsentry/sentry-kafka-management; 25. getsentry/sentry-kafka-schemas; 26. getsentry/sentry-protos; 27. getsentry/sentry-redis-tools; 28. getsentry/service-registry; 29. getsentry/skrooge; 30. getsentry/snuba-sdk; 31. getsentry/statsdproxy; 32. getsentry/status-page-list; 33. getsentry/streams/sentry_streams; 34. getsentry/symbolic; 35. getsentry/taskbroker/clients; 36. getsentry/usage-accountant; 37. getsentry/watto; 38. getsentry/sentry; 39. getsentry/snuba; 40. getsentry/vroom; 41. getsentry/relay; 42. getsentry/symbolicator; 43. getsentry/taskbroker; 44. getsentry/uptime-checker; 45. getsentry/launchpad; 46. getsentry/self-hosted.getsantry[bot], created at 2026-08-15T17:06:41Z. (meaning Aug 15, 2026){"permission":"none","role_name":""}./home/byk/Code/getsentry/security-as-code/rbac/env/prod/team/engineering/release-approvers.tf defines module team-group--release-approvers, source ../../../../module/group/team, with team = "release-approvers", display name Team Release Approvers, and description “People who can approve releases in GitHub.” Owner is chadwhitacre@sentry.io; direct members are alex.jillard@sentry.io, alexander.weber@sentry.io, bruno@sentry.io, dgriesser@sentry.io, fpacifici@sentry.io, francesco.novy@sentry.io, hubert.deng@sentry.io, indragie.karunaratne@sentry.io, james.keane@sentry.io, jan.auer@sentry.io, matej.minar@sentry.io, michael.hoffmann@sentry.io, pierre.massat@sentry.io, stephanie.anderson@sentry.io, thomas.hu@sentry.io, and trent.schmidt@sentry.io; sub-team is team-devinfra@sentry.io.security-as-code. It identified a compatibility exception: auto-approved releases use getsantry[bot], which has no collaborator role on the target repository; any guard should exempt only that existing trusted automation path.admin, read, or write repository access, while outside collaborators cannot join teams. It states visible teams are viewable and mentionable by all organization members, while secret teams are visible only to team members and organization owners and cannot be nested. Nested child teams inherit parent repository access; e.g., granting Engineering write grants that access to Application Engineering and Identity child-team members. GitHub recommends auditing existing repository access before nesting teams and preparing by: 1. removing all existing team members; 2. auditing/adjusting permissions and assigning parents; 3. creating new teams, selecting parents, and granting access; 4. adding people directly to teams.write or admin access on the target repository, queried with the existing release-bot installation token. It stated this preserves security-as-code privacy and leaves that repository responsible for granting contractors limited publish triage access, while preventing that triage access from approving releases for unrelated repositories.