Increased security on Hosting team repositories

For years, HostingHosting A web hosting service is a type of Internet hosting service that allows individuals and organizations to make their website accessible via the World Wide Web. team contributors have followed team protocols without issue, and that speaks very highly of the professionalism of this team. In recent days, however, team repositories have received an increase in spammy Pull Requests, premature merges, and other undesirable activity in the repositories. Because of this, branch protection rules on all Hosting team repositories have been tightened.

Moving forward, the following security protocols are being enforced:

  • Two approvals are required for a PR to be merged. This doesn’t mean one approval, this doesn’t mean two reviews, this doesn’t mean that folks can ignore change requests and/or bypass the 2 review rule and merge PRs anyway. This means that PRs can not be merged without two approvals.
  • Change requests must be marked as resolved for a PR to be merged. If there are unresolved change requests, the PR can not be merged.
  • New pushes must be reviewed and approved prior to merging. If new code is pushed to a PR, two reviews and approvals of that code must be made in order for the PR to be merged.
  • New GitHubGitHub GitHub is a website that offers online implementation of git repositories that can can easily be shared, copied and modified by other developers. Public repositories are free to host, private repositories require a paid subscription. GitHub introduced the concept of the ‘pull request’ where code changes done in branches by contributors can be reviewed and discussed before being merged be the repository owner. accounts can not interact with the repositories. If you’re a new contributor who just created your Github account, there is a 24 hour grace period before you can interact with the repos.
  • All unit tests must pass for a PR to be merged. There should be only green check marks in test results before hitting merge. If any tests are failing, resolve the issue before merging.

Exceptions:

  • Administrators of the Github WordPress organization can bypass these rulesets on all repositories.
  • Administrators of the Github WordPress Hosting Team can bypass these rulesets on all repositories.
  • Repository Maintainers can bypass these rulesets on the Runner repository.
  • Members of the Github Hosting Team have the ability to bypass these rules on the Hosting Handbook and Advanced Administration Handbook repositories. This is to be used under extenuating circumstances only. If team members abuse this privilege it will be revoked.

These rules are meant to protect the repositories, particularly the test runner, from premature, spammy and malicious merges.

Contributors – Please hop into the #hosting SlackSlack Slack is a Collaborative Group Chat Platform https://slack.com/. The WordPress community has its own Slack Channel at https://make.wordpress.org/chat/ channel and pingPing The act of sending a very small amount of data to an end point. Ping is used in computer science to illicit a response from a target server to test it’s connection. Ping is also a term used by Slack users to @ someone or send them a direct message (DM). Users might say something along the lines of “Ping me when the meeting starts.” @amykamala if you run into any issues with these new rules. Thank you all for your contributions to the Hosting team and happy contributing!

Call for feedback: Real-time Collaboration (RTC) server-aware approach

Hey hosts 👋

Testing and development on the real-time collaboration feature (“RTC”) has picked up again after initially being removed from WordPress 7.0. A new serverServer A server is a piece of computer hardware or software that provides functionality for other programs or devices. Typical servers are database servers, file servers, mail servers, print servers, web servers, game servers, and application servers.-aware approach for RTC is being explored, and feedback from you and your teams is needed!

Three candidates for server-aware sync engines are being developed in a pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory or can be cost-based plugin from a third-party.. Hosts are invited to test the implementations, with a focus on performance, and provide feedback along with any supporting data. Responses from hosts will affect the direction of the feature moving forward.

How to test

The new exploration of sync engine candidates is happening in a Gutenberg Sync Engines repository, which can be installed in WordPress as a standalone plugin. The engines being explored are Yjs–server, Distributed Editing (DE-RTC), and Intent log, which all tackle previous bottlenecks that affected RTC performance. The goal for this exploration is to identify the most ideal candidate and then move forward with further testing on that as a feature pluginFeature Plugin A plugin that was created with the intention of eventually being proposed for inclusion in WordPress Core. See Features as Plugins.

Feedback can be shared on the original post and/or in the #feature-realtime-collaboration channel on SlackSlack Slack is a Collaborative Group Chat Platform https://slack.com/. The WordPress community has its own Slack Channel at https://make.wordpress.org/chat/.

More information is available here:

Many hosts and hostingHosting A web hosting service is a type of Internet hosting service that allows individuals and organizations to make their website accessible via the World Wide Web. team members previously shared thoughts and data about the initial implementation of RTC, and contributed with testing, which was so helpful! Additional testing of this new direction in a variety of server environments will not only benefit development but will also help assure compatibility and smooth performance on your hosting infrastructure. Contributions through testing on the part of web hosts always help keep the development process informed and are so valuable to the WordPress Open SourceOpen Source Open Source denotes software for which the original source code is made freely available and may be redistributed and modified. Open Source **must be** delivered via a licensing model, see GPL. Project!

Thank you all for participating in testing this feature!

Props to @amykamala for collaborating on this post.

Hosting Team Meeting Agenda 2026-09-30

Next Meeting

The next meetings will be in the #hosting SlackSlack Slack is a Collaborative Group Chat Platform https://slack.com/. The WordPress community has its own Slack Channel at https://make.wordpress.org/chat/ channel on Wednesday, September 30, 2026 at 0900 UTC and Wednesday, September 30, 2026 at 1800 UTC. Hope to see you there!

Agenda

HostingHosting A web hosting service is a type of Internet hosting service that allows individuals and organizations to make their website accessible via the World Wide Web. team

  • Increased branch protections on all repos
  • Discussion: Archiving the Reporter repo in lieu of the CoreCore Core is the set of software required to run WordPress. The Core Team builds WordPress. reporter repo.
  • Tickets/PRs

Open Floor

Anything else? Please leave a comment with any additions or suggestions for the meeting.

#agenda, #hosting-community, #meetings, #weekly-hosting-chat

Hosting Team Meeting Agenda 2026-09-23

Next Meeting

The next meetings will be in the #hosting SlackSlack Slack is a Collaborative Group Chat Platform https://slack.com/. The WordPress community has its own Slack Channel at https://make.wordpress.org/chat/ channel on Wednesday, September 23, 2026 at 0900 UTC and Wednesday, September 23, 2026 at 1800 UTC. Hope to see you there!

Agenda

WordPress News

HostingHosting A web hosting service is a type of Internet hosting service that allows individuals and organizations to make their website accessible via the World Wide Web. Team

  • Tickets/PRs

Open Floor

Anything else? Please leave a comment with any additions or suggestions for the meeting.

#agenda, #hosting-community, #meetings, #weekly-hosting-chat

Hosting Team Meeting Agenda 2026-09-16

Next Meeting

The next meetings will be in the #hosting SlackSlack Slack is a Collaborative Group Chat Platform https://slack.com/. The WordPress community has its own Slack Channel at https://make.wordpress.org/chat/ channel on Wednesday, September 16, 2026 at 0900 UTC and Wednesday, September 16, 2026 at 1800 UTC. Hope to see you there!

Agenda

WordPress News

HostingHosting A web hosting service is a type of Internet hosting service that allows individuals and organizations to make their website accessible via the World Wide Web. Team

  • Tickets/PRs

Open Floor

Anything else? Please leave a comment with any additions or suggestions for the meeting.

Props to @chaion07 for collaborating on the agenda.

#agenda, #hosting-community, #meetings, #weekly-hosting-chat

Hosting Team Meeting Agenda 2026-09-09

Next Meeting

The next meetings will be in the #hosting-community channel on Wednesday, September 9, 2026 at 0900 UTC and Wednesday, September 9, 2026 at 1800 UTC. Hope to see you then!

Agenda

WordPress News

HostingHosting A web hosting service is a type of Internet hosting service that allows individuals and organizations to make their website accessible via the World Wide Web. Team

Open Floor

Anything else? Please leave a comment with any additions or suggestions for the meeting.

Props to @amykamala for assisting with this agenda.

#agenda, #hosting, #meetings, #weekly-hosting-chat

WordCamp US 2026 Contributor Day Recap

The HostingHosting A web hosting service is a type of Internet hosting service that allows individuals and organizations to make their website accessible via the World Wide Web. Team joined forces in person on August 16th at the Phoenix Convention Center during WordCampWordCamp WordCamps are casual, locally-organized conferences covering everything related to WordPress. They're one of the places where the WordPress community comes together to teach one another what they’ve learned throughout the year and share the joy. Learn more. US 2026 Contributor DayContributor Day Contributor Days are standalone days, frequently held before or after WordCamps but they can also happen at any time. They are events where people get together to work on various areas of https://make.wordpress.org/ There are many teams that people can participate in, each with a different focus. https://make.wordpress.org/support/handbook/getting-started/getting-started-at-a-contributor-day/. The table was led by @jazzs3quence and @amykamala, with contributors working in person in Phoenix and remotely through the #hosting Slack channel and GitHub. Thank you to everyone who joined! The team came together in the spirit of collaboration, built momentum with a sharp focus on problem solving, and moved team projects forward! The plan for the day held up well, and work landed in multiple areas.

WordPress 7.0 and 7.1 serverServer A server is a piece of computer hardware or software that provides functionality for other programs or devices. Typical servers are database servers, file servers, mail servers, print servers, web servers, game servers, and application servers. compatibility documentation

Server Compatibility documentation protocols were updated: recommendations are no longer being posted on Make /hosting, and instead have been moved to the Hosting Handbook as individual pages. The Hosting Handbook, as a result, gained two new server compatibility pages for WordPress 7.0 and WordPress 7.1, closing issues #393 and #397. Both pull requests (#414, #415) were reviewed and merged during the event, and the 7.0 post was published, while the 7.1 post was prepared and scheduled to publish for the pending release.

Testing tools maintenance

On the PHPUnit Test Runner, a push towards multi-environment reporting, spearheaded by @jazzs3quence, made progress with updated pull requests, and testing done on both Pantheon and BlueHost hosting infrastructure. We’re still looking for more hosts to review the PR (updated ahead of CD by @dilip2615) and test in their environments to solidify the current direction or identify where iteration or changes are needed. @jazzs3quence merged @desrosj‘s documentation updates (#256), a pull request that had been waiting for a while, along with two dependency updates (#330 and #332). The WCUS26 label still lists runner and reporter tickets that are ready for anyone who wants to keep going.

Advanced Administration Handbook: multisiteMultisite Multisite is a WordPress feature which allows users to create a network of sites on a single WordPress installation. Available since WordPress version 3.0, Multisite is a continuation of WPMU or WordPress Multiuser project. WordPress MultiUser project was discontinued and its features were included into WordPress core. Advanced Administration Handbook -> Create A Network. refresh

Multisite documentation received some attention. @derintolu opened twelve pull requests (#509 to #516 and #518 to #520), replacing screenshots from 2018 and 2019 with captures from WordPress 7.0.4, correcting the network admin guidance, and swapping out retired Codex links. @superdav42 reworked the multisite introduction (#508) and modernized the administration guidance (#517).

A structural proposal also came out of the day: a series of pull requests (#418 to #423) that would move the hosting-owned Advanced Administration pages into the Hosting Handbook, merging them into the existing reliability, security, performance, server environment, and multisite pages. These are open for review and feedback is welcome on the pull requests.

There was a discussion with the Documentation and MetaMeta Meta is a term that refers to the inside workings of a group. For us, this is the team that works on internal WordPress sites like WordCamp Central and Make WordPress. teams around the idea of retiring the Advanced Administration Handbook. The conversation is still open with the Documentation team, who has offered to take over maintenance of the handbook to prevent it from being retired.

AI

A discussion was opened about the use of AI, which resulted in a new official team policy requiring contributors to disclose when AI is used.

The new 7.0 Compatibility page was marked as AI assisted (#424) in line with the team’s new AI policy.

Hosting Handbook PR #417 was opened to add claude.md and agents.md files to the Advanced Admin Handbook repository, with agent instructions and a maintenance reference for the repo.

New Contributors

A number of seasoned contributors joined the Hosting team table this year and it was so amazing to see everyone! The Hosting team also welcomed two new contributors: a teenager who signed up for wp.org, SlackSlack Slack is a Collaborative Group Chat Platform https://slack.com/. The WordPress community has its own Slack Channel at https://make.wordpress.org/chat/, and GitHubGitHub GitHub is a website that offers online implementation of git repositories that can can easily be shared, copied and modified by other developers. Public repositories are free to host, private repositories require a paid subscription. GitHub introduced the concept of the ‘pull request’ where code changes done in branches by contributors can be reviewed and discussed before being merged be the repository owner. and then reviewed Hosting Handbook PR #413, and a middle schooler who made this Galaxy Wapuu at the Hosting team table:

These two are now the youngest Hosting Team contributors!

More Tickets and Pull Requests

Hosting Handbook

  • Issue #416: created and resolved during the event, adding a public link to the rendered Advanced Administration Handbook.
  • PRs #414 and #415: WordPress 7.0 and 7.1 server compatibility documentation, merged.
  • PR #424: marked the 7.0 compatibility page as AI assisted, merged.
  • PR #417: added agent instructions and a maintenance reference for the repository, open.
  • PRs #418, #419, #420, #421, #422, #423: the Advanced Administration consolidation series, open for review.

Advanced Administration Handbook

  • PRs #509 to #516 and #518 to #520: multisite documentation fixes and screenshot refresh by @derintolu, open for review.
  • PRs #508 and #517: multisite introduction and administration modernization by @superdav42, open for review.

PHPUnit Test Runner

  • PR #256: documentation updates by @desrosj, merged.
  • PRs #330 and #332: dependency updates, merged.

The contributions did not stop with the event. During the week that followed, @johnbillion documented the hash extension requirement (#425), @amykittenkamala cross-linked the 7.0 and 7.1 compatibility pages (#426, merged), and @ekamran added version-pinned WP-CLIWP-CLI WP CLI is the Command Line Interface for WordPress, used to do administrative and development tasks in a programmatic way. upgrade commands (#427) and fixed the GitHub capitalization across the handbook (#428, merged).

Contributors

In alphabetical order: @amykamala, @ArnasDon, @bordoni, @chrisdavidmiles, @jazzs3quence, @netti3, @sirjonathan.

Contributing through GitHub: @derintolu, @desrosj, @superdav42.

If you contributed and your name is missing, please leave a comment to be added.

Thank you to everyone who spent their Sunday moving these projects forward. Most of the pull requests above are still open, and reviews are welcome on all of them.

Props to @bordoni and @amykamala for collaborating on this post.

Post contents were AI assisted.

X-post: The Core Security Initiative

X-comment from +make.wordpress.org/security: Comment on The Core Security Initiative

Hosting Team Meeting Agenda 2026-09-02

Next Meeting

The next meetings will be in the #hosting channel on Wednesday, September 02, 2026 at 0900 UTC and Wednesday, September 02, 2026 at 1800 UTC. Hope to see you then!

Agenda

WordPress News

HostingHosting A web hosting service is a type of Internet hosting service that allows individuals and organizations to make their website accessible via the World Wide Web. Team

Open Floor

Anything else? Please leave a comment with any additions or suggestions for the meeting.

#agenda, #hosting-community, #meetings, #weekly-hosting-chat

Hosting Team AI Policy

Heads up HostingHosting A web hosting service is a type of Internet hosting service that allows individuals and organizations to make their website accessible via the World Wide Web. Team, an official new policy is now in effect:

Use of AI in Hosting Team content and submissions must be disclosed.

If AI has been used to generate or process contribution submissions, that use of AI must be disclosed as part of the submission and content. This applies to any and all Hosting Team content, including PRs, posts, emails, graphics, meetings, summaries, comments, and any other materials that have been created or manipulated by AI.

Disclosure can be done at the bottom of the content in question using a simple AI Assisted watermark/text.

Folks are welcome to discuss this in the comments. This policy is preliminary, but official, and it can be / may be updated in the future.

Anything else? Let us know in the comments.

Props to @jazzs3quence and @chrisdavidmiles for reviewing this post!