Maybe we should also change permissions to create private streams to admins and mods.
It might be a good idea to rename a few things
E.g. rename "general" to "community" so people expect more chatiness in that channel
It might also be useful to have an "announcement" stream that people are auto-subscribed to
Did you read the article @Don Sizemore sent WRT to the slow death of Google Groups? I've seen Zulip allows for an inbound mail message stream. Dunno if that might be worth a try to migrate a few things to Zulip in one go. We could for example make the low frequency groups like dataverse-dev etc a Zulip stream. And maybe create one for security. Dunno...
By "closed" you mean "private". I think "core team" is the only one.
So far it's the only one, yes
It might be interesting to have a security channel which is private with history blank for new people joining
We could tell people to reach out to us on the community channel if they find a security thing and talk with them in such a channel
Maybe, but our current practices around security chatter are probably ok. New topic, please, and probably not right now. :happy:
Changed the topic so we can pick it up again later
That's fine but it's a big lift. You'd need to convince lots of people to join Zulip first.
People are starting to join! :tada:
Is the following possible with Zulip? Or just a dream? "It might be interesting to have a security channel which is private with history blank for new people joining"
Huh. Interesting. Thanks.
Here's the current topic in the new security channel:
"A placeholder security stream to redirect to proper channels: security@dataverse.org and/or https://github.com/IQSS/dataverse-security โ Please don't post sensitive information here."
Is a read-only stream possible? If so, maybe the #security stream could have a single topic/message saying:
"To report security issues, please email or security@dataverse.org create an issue at https://github.com/IQSS/dataverse-security"
As a reminder, in 5.13 we wrote up our current practices at https://guides.dataverse.org/en/5.13/developers/security.html
We can certainly change things and edit that page! :happy:
I just wanted to get ahead of someone jumping in and posting something sensitive. Read-only sounds great. It could be a private stream if we want to assume the risk that Zulip content will never be leaked?
There's a "who can post to the stream" dropdown in that screenshot above. ^^
I guess that's how we could make it read only to non-admins.
(Right now "everyone" can post to #security .)
We just got a security report in #security . Is that what we want?
I just started a new topic about this: #security > discuss security elsewhere?
Philip Durbin ๐ said:
I just started a new topic about this: #security > discuss security elsewhere?
Huh. That topic is gone now. Not sure why.
Anyway, an enthusiastic security researcher is DMing some of us. :smile:
I'm not sure if a private channel for security is better or not. ![]()
As community members usually don't have access to the IQSS Slack, doing something here would probably be nice.
If there are concerns about security of that channel, we could also use an E2E encrypted Matrix room
That's not perfect either, but probably better than Zulip
I like topics in Zulip much better than threads in Matrix.
Last updated: May 30 2026 at 09:11 UTC