Community summit discussion notes: Revitalizing contributor teams’ leadership pipeline

Title of session: Revitalizing Contributor Teamsโ€™ Leadership Pipeline

Facilitator: @cbringmann

Notetakers: @ninianepress, @peiraisotta

Personal check-in about the topic

How do we feel about the leadership pipeline?

Discussion objectives

  • Identify the challenges to the current leadership
  • Explore motivations for folks becoming leaders
  • Discuss barriers that prevent people from embracing leadershipย 
  • Brainstorm potential solutions
  • Identify future pipelines

Key points

Identify the challenges to the current leadership

We donโ€™t know what we are doing โ€“ things work, but we donโ€™t know why weโ€™re doing specific things.

Thereโ€™s a different onboarding experience for each team and personal unstructured mentorships, but we donโ€™t know all the things that we have the power to do or all the tools that are available.

Team reps donโ€™t have clear instructions; we have followed some guidelines without knowing the reason why those guidelines are in place.

Burnout and overwhelm are a reality and the confusion doesnโ€™t help.

Thereโ€™s a particular challenge in understanding what is a โ€œleaderโ€ in our ecosystem:ย 

  • Leadership: whoever is very active in the projects (WordCampWordCamp WordCamps are casual, locally-organized conferences covering everything related to WordPress. They're one of the places where the WordPress community comes together to teach one another what theyโ€™ve learned throughout the year and share the joy. Learn more. and MeetupMeetup All local/regional gatherings that are officially a part of the WordPress world but are not WordCamps are organized through https://www.meetup.com/. A meetup is typically a chance for local WordPress users to get together and share new ideas and seek help from one another. Searching for โ€˜WordPressโ€™ on meetup.com will help you find options in your area. organizers, folks heavily involved in the releases and projects being sustainable, etc. and not only team reps)

From other sessions we realized the lack of definition of what team repTeam Rep A Team Rep is a person who represents the Make WordPress team to the rest of the project, make sure issues are raised and addressed as needed, and coordinates cross-team efforts. is, but we know that itโ€™s not necessarily a lead. So, we donโ€™t have a structure to define what a leader is in this community. People who are louder might be perceived as leaders leaving behind other folks. Formally, the only clear definition is a project lead.

Community members expect organizers and team reps to have all the answers, but many times leaders donโ€™t have answers or the power to make the change requested. It causes a frustrating feeling that we do and donโ€™t have the power to create positive change.

Thereโ€™s a real need for clarity since thereโ€™s a lack of documentation for stewardship roles, and people have to:

  • Make mistakes and ask for forgiveness in retrospect
  • Be pushy and take initiative

People expect team reps to move things forward, but thereโ€™s no clear way forward often, no documentation, and itโ€™s clear reps canโ€™t do whatever they want. This makes it incredibly difficult to get anything done.

Itโ€™s difficult to find people who are willing to share responsibilities in local teams:

  • Thereโ€™s a lot of focus on global stewardship, but not enough for local communities.

If we donโ€™t have a clear idea about the responsibilities of a leadership role, we canโ€™t onboard new leaders.

New contributors think they can only contribute to small tasks and they donโ€™t realize they can become a team rep.

Leadership onboarding doesnโ€™t exist on all teams and projects.

Thereโ€™s a lack of connection between local teams and their respective global teams.

Explore what motivates folks into becoming leaders

  • Desire to learn as well as a love of learning by doing, and contributing
  • Desire to support and empower others
  • Maintaining and supporting a local community or project
  • Filling a gap, no motivation
  • Feeling empowered and helping others empower themselves
  • Seeking opportunities to fix things and knowing that weโ€™re making progress (Ex. a high number of closed tickets)
  • Learning how the whole project works โ€“ the challenge of getting to learn how everything is connected is the motivation

Discuss barriers that prevent people from embracing leadership roles

  • Contributors arenโ€™t aware about the possibility of growing into leadership roles.
  • The contributor pipelines are clearer on some teams than others.
  • There are knowledge barriers with a lack of documentation on many teams.

Brainstorming potential solutions

  • Better documentation and maybe a few centralized places for the documentation that is needed by different teams:
    • โ€œWhat is leadershipโ€ in General Documentation or the Marketing Team, and maybe linked to team pages on how reps work on their team as well as what the role looks like and what it takes.
    • Further asynchronous discussion will be needed.
  • Request the information that is missing
  • Create an auto-updating chart on WordPress.org or where ever we can find the people responsible of each project and team
  • Leadership training: give contributors the path and tools to develop their leadership skillsย 
  • Mentorships to help contributors look for opportunities since current leaders can recognize future ones and can help them step into the role little by little
  • Small steps into the role
  • Keeping and maintaining the human component related to leadership without getting lost in process

What are the incentives to being a rep?

  • Every successful contribution helps as a learning opportunity that leaves reps feeling empowered to lead.
  • When a rep is able to lead someone, it further helps develop their skills, which feels great, especially when the project moves forward.
  • Some reps have no motivation to lead, they just became leaders because they were told by others to fill the open, much-needed position.
    • You can lead and inspire without being a rep.
  • In some cases, thereโ€™s an aspect of mentorship where if someone notices your hard work and says the role could be a good fit for you, it can snowball; it can be really encouraging and motivating.
  • Knowing your contributions are live for over 40% of the (public) web.
  • You donโ€™t need to be a rep to learn a lot, but it does happen.
  • There are a lot of opportunities on the Test Team and other Teams.
  • You can start to see where there are gaps that need to be bridged.
  • Learning how everything works can be really motivating.
  • Having a role where success objectives are clearly defined such as counting the number of closed tickets is definitely motivating for many.
  • The trust everyone puts in you is empowering.
  • Helping foster a strong sense of community is motivating.
  • Human connection and making life-long friendships.

Identify future pipelines

  • Starting or facilitating meetups and being active in the community can help someone spot you to encourage you into a leadership role.
  • One of the jobs as a rep isnโ€™t just to lead, but to see and encourage others.
  • Mentorships and documentation are key.
  • Create a system to ensure that the current leaders support the next ones by mentoring them and walking them through the leadership path
  • Standardize badge system including leadership badges
  • Standardize training path to leadership (to get the badge folks have to take specific course) and we could use material already available on the Learn platform, or decide whatโ€™s needed during contributor days
    • Courses or to-do lists may not be accessible for everyone, unless theyโ€™re short and concise
  • Expand and standardize leadership roles to include something like junior and senior reps both globally and per team
  • Offboarding process for when leaders want to step back (information transfers, access removal, etc.)
  • Process to transfer the knowledgeย 
  • Defining leadership roles is crucial for reps but also for working groups
  • Visuals are needed to understand the structure of everything
    • Thereโ€™s already a Marketing issue in GitHubGitHub GitHub is a website that offers online implementation of git repositories that can easily be shared, copied and modified by other developers. Public repositories are free to host, private repositories require a paid subscription. GitHub introduced the concept of the โ€˜pull requestโ€™ where code changes done in branches by contributors can be reviewed and discussed before being merged be the repository owner. https://github.com/ for this idea
  • Too much bureaucracy can be a barrier to entry for new(er) contributors
  • Using accessible tools is critical as Google Docs isnโ€™t accessible

#summit, #summit-2023, #team-reps

Community Summit Discussion Notes: PHP version support

Title of Session: PHPPHP PHP (recursive acronym for PHP: Hypertext Preprocessor) is a widely-used open source general-purpose scripting language that is especially suited for web development and can be embedded into HTML. https://www.php.net/manual/en/preface.php. version support

Facilitator: @mikeschroder

Notetaker 1: @flixos90

Notetaker 2: @courane01

From the session schedule:

Currently, WordPress does not officiallyย fullyย support PHP 8.0+. This discussion will focus on how WordPress can support and align with modern PHP versions, and how to drop support for PHP versions that are end-of-life (โ€œEoLโ€). There is urgency to this as PHP 8.0 will be EoL in November, and PHP 7.4 reached EoL last November.

Raw Notes

  • Several hosting providers expressing support for running automated tests for PHP version support across hosting providers
  • Is WordPress 6.3 fully supporting PHP 8? โ€“ Basically yes (PHP 8.0 and 8.1 compatible with known exceptions, TracTrac Trac is the place where contributors create issues for bugs or feature requests much like GitHub.https://core.trac.wordpress.org/. tickets available for all exceptions) https://make.wordpress.org/core/2023/06/20/proposal-criteria-for-removing-beta-support-from-each-php-8-version/ย 
  • PHP 8 โ€œbetaBeta A pre-release of software that is given out to a large group of users to trial under real conditions. Beta versions have gone through alpha testing in-house and are generally fairly close in look, feel and function to the final product; however, design changes often occur as part of the process.โ€ tag was removed after WP 6.3 release https://make.wordpress.org/core/handbook/references/php-compatibility-and-wordpress-versions/ย 
  • Encourage/support plugins supporting it
  • Attention was raised for Julietteโ€™s published post asking for support on WPCSWordPress Community Support A public benefit corporation and a subsidiary of the WordPress Foundation, established in 2016. which is critical to facilitate PHP version support in the future https://make.wordpress.org/core/2023/08/21/wordpresscs-3-0-0-is-now-available/ย 
  • Hosting teamโ€™s PHP test runner project (running coreCore Core is the set of software required to run WordPress. The Core Development Team builds WordPress. unit tests on several hosts) has issues with PHP 8 โ€“ who can help fix/maintain this project? https://make.wordpress.org/hosting/test-results/ย 
  • PHP 5.6 support being dropped in WP 6.3 hopefully encourages hosting providers to jump up to supporting more recent PHP versions including 8+
  • PHP version usage of WP sites
  • Big push on GoDaddy to get sites on PHP 8+, vast majority of migrations (>70%) has gone smoothly (~18% marked as โ€œhigh riskโ€ updates)
  • Bluehost checking factors like closing body tags, document size changing etc.
  • Is there room to open-source tooling for checking that PHP update was successful or is causing errors on the site?
  • While thereโ€™s a desire in collaborating on tools across hosting providers, historically differences between platforms has hindered that โ†’ knowledge sharing rather than actual tooling
  • Users donโ€™t care what version of PHP they are on, managed hosts manage that for them
  • Can we use WP-CLIWP-CLI WP-CLI is the Command Line Interface for WordPress, used to do administrative and development tasks in a programmatic way. The project page is http://wp-cli.org/ https://make.wordpress.org/cli/ for supporting updates? Useful by hosts
  • Min/max for PHP for the plugins/themes
    • Max version hasnโ€™t been needed before
    • List of deprecations that would cause PHP incompatibility, run a scanner.ย 
    • Max version puts the work on pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party/theme maintainers, and less useful.ย 
  • Implement automated scanner in plugin and theme directories to detect PHP version issues โ†’ responsibility of metaMeta Meta is a term that refers to the inside workings of a group. For us, this is the team that works on internal WordPress sites like WordCamp Central and Make WordPress. team
  • Paid plugins have another issue: many sites no longer have active licenses and therefore donโ€™t receive the updates that would add PHP 8+ support
  • WP plugin repository is not able to force-update premium plugins, particularly if they use the new upgrade URI headerHeader The header of your site is typically the first thing people will experience. The masthead or header art located across the top of your page is part of the look and feel of your website. It can influence a visitorโ€™s opinion about your content and you/ your organizationโ€™s brand. It may also look different on different screen sizes. introduced a while ago (which bypasses wp.org completely)
  • Steps to encourage plugin support
    • email plugin authors prompting to update, but anticipate plugins to endย 
    • display info on plugin page
    • integrate into Plugin APIAPI An API or Application Programming Interface is a software intermediary that allows programs to interact with each other and share data in limited, clearly defined ways., health check could warn themย 
  • Security plugins could tackle Tide scores and compatibility โ€“ WP Scan mentioned as a possible option
  • Resources:
  • For the bulk of sites, ensuring PHP support of ~50 most popular plugins will be enough, then the long tail of 100s or 1000s of plugins only applies to a relatively smaller amount
  • What educational resources can LearnWP create to help educate on what/why/how to update? https://github.com/WordPress/Learn/issues/new?assignees=&labels=Awaiting+Triage%2C+Needs+Subject+Matter+Expert&projects=&template=topic-idea.md&title=Topic+Idea%3A+TOPIC+TITLE
    • How to start contributing to PHP areasย 
  • Speed at which we drop older versions of PHP โ€“ can we correlate versions of WP with PHP?
    • Who can update the PHP? Often hosts deployDeploy Launching code from a local development environment to the production web server, so that it's available to visitors. it
  • Current 5% rule is based on overall WP sitesโ€™ PHP version usage, could we make it based on only recent WP version sitesโ€™ PHP version usage? โ€“ That would not make a notable difference, there is not a real correlation between using old WP versions and PHP versions, which makes sense since the hosting provider controls PHP support regardless of WP. wp.org internally has that data available, and itโ€™s only ~0.1% different from overall PHP version usage.
  • Extender ecosystem is waiting on Core
  • Bottleneck of keeping upย 
  • How can we keep support financially or with labor long-term maintenance of the WPCS / PHP compatibility tooling?
    • Long-term additional contributors would be great, but short-term the barrier of entry to this work is so high that support of the existing contributors is essential
    • Generally, the WP project is focused on getting more contributors, but sometimes there may be more value in identifying and funding already experienced contributors, or attract specific contributors with specific expertise needed
    • mentorship for PHP niche areas, separated out from the rest of Core new contributor tableย 
  • Conclusion
    • Find funding for contributors and tooling, also mentoring
    • repo plugins to WP users
    • Hosting companies working together to find common versions encounter errors

#summit, #summit-2023

Community Summit Discussion Notes: Can WordPress become the household name it deserves to be?

Title of Session: Can WordPress become the household name it deserves to be?

Facilitator: @dtsears

Notetaker 1: @mikachan

Notetaker 2: @jessibelle

From the session schedule:

WordPress is the internetโ€™s best kept secret. What would it take for WordPress to be able to raise awareness about itself and elevate the value of the ecosystem, while being thoughtful on behalf of the community that surrounds it?

Key Points

  • We began the discussion by highlighting important historical events, starting with things that have encouraged market adoption, for example:
    • When Movable Type changed its license
    • When Custom Post Types were introduced
    • Adding import/export functionality
    • Ability to make multilingual sites
    • Amount of developer support, so easy for new users to pick up
  • We discussed the importance of WordPress being a household name, including the why and the how. Some highlights include:
    • WP levels the playing field for small businesses to have the same good quality websites as larger companies. The most important people are the people who donโ€™t have big budgets.
    • The flexibility of WP means that itโ€™s unlikely to be stopped by new trends.
    • Brand awareness โ€“ it is not self-sustaining and is sustained by the extremely active community.
    • Expanding the reach of WP โ€“ Lack of next-generation WP users. Explore the social side of WP โ€“ make it a social network? Connect things as part of the open web rather than the closed web. Elevate WP to provide exposure to content.
    • WP not seen as serious career option, but for some people its the beginning of their career.
  • We concluded by discussing current challenges and the next steps

Action Items/Next Steps:

  • Ideas to address different audience segments:
    1. Audience segmentation โ€“ create the top 8-10 audiences (developers, small-business, enterprise, marketers)
    2. Group the audiences into categories (end-users, makers)
    3. Segment messaging to those categories (lots of different pathways)
  • Tutorials need to be updated. Being out-of-date and inconsistent puts new users off and breaks trust. Backwards compatibility with tutorials โ€“ can we mark them as deprecated? Use Playground to keep tutorials up to date.
  • Teach new translators using better tutorials.
  • Make the process to update docs content more obvious. See Mozilla onboarding for documentation.
  • WordPress.tv โ€“ alleviate this tool we already have. Surface video content in the WP backend, along with docs and other content.
  • Use WP Playground more in tutorials
  • Improve onboarding on all levels (new users, new contributors). See Mozilla onboarding for a good example.

Raw Notes

Continue reading โ†’

#summit, #summit-2023

Community Summit Discussion Notes: Refreshing the contributor pipeline

Title of Session: Refreshing the contributor pipeline

Facilitator: @volkswagenchick

Notetaker 1: @mikachan

Notetaker 2: @evarlese

From the session schedule:

A healthy contributor pipeline requires new contributors! Prior to the pandemic, our in-person events were key to welcoming and engaging new contributors. With events slower to return, how can we continue to connect with and bring in new contributors? This discussion will explore where Make Teams are currently seeing new contributors from, and brainstorm what kind of outreach the WordPress project could do to refresh the contributor pipeline. An additional focus for this discussion will be around how to continually retain new contributors.

Key Points

  • Community Team spent 2022 re-activating the community.
  • The Docs team is an inspirational team, both in how they attract new contributors and how they support people longer-term ๐Ÿช
  • The pandemic immensely impacted the community; there is a lot of work done at in-person events and we lost that.
  • There is a new Contribute page on Make WP.
    • Ideally, weโ€™d also have a โ€œgetting set upโ€ page that includes how to set up SlackSlack Slack is a Collaborative Group Chat Platform https://slack.com/. The WordPress community has its own Slack Channel at https://make.wordpress.org/chat/., find your team meetings etc.
  • There are no longer enough people to help organise in-person events as the momentum has been lost post-pandemic.
  • The need to go to the larger WordCamps because the local ones no longer happen.
  • People tend to be more passionate at local events.
  • Personal connections are important.
  • Recent mentorship program has been extremely successful.
  • What is the reward? What are people getting from contributing?
    • Reframing why we contribute โ€“ what open sourceOpen Source Open Source denotes software for which the original source code is made freely available and may be redistributed and modified. Open Source **must be** delivered via a licensing model, see GPL. is on a broader scale. Youโ€™re helping the wider community, keeping the software free.
  • Badges are an under-utilised component, and WP profiles could be improved.
  • Lack of contributor data.
  • Reframe โ€œoffice hoursโ€ to AMAs โ€“ everyone can help everyone, eases the pressure on the usual few people.
  • Big challenge is that there is a completely different repo for every single team. Overwhelming. GH and tracTrac Trac is the place where contributors create issues for bugs or feature requests much like GitHub.https://core.trac.wordpress.org/. are very overwhelming for new contributions. Do we need some consistency across the different repos?
  • We should recruit more contributors from external projects.

Action Items/Next Steps:

  • Create a โ€œgetting set upโ€ page alongside the new Contribute page, for each Make team.
  • Create a contributor tool CTA that takes people to the Contributor page.
  • We also need a clear pathway for people who get stuck or need help โ€“ add a direct link to the public-mentoring channel to ask for help on anything from the contributor team handbook pages.
  • Recruit more organisers for in-person events.
  • What can other teams learn from the Docs team?
  • Revisit Google Summer of Code as a way to recruit new contributors. Look for other ways to recruit externally to the WP community.
  • Set up support for existing contributors to become mentors to new contributors.
  • Be consistent with whatโ€™s included on each Make team handbook, how can people ask for help? Add link to mentoring channel.
  • Explore introducing a more immediate attribution system โ€“ get the โ€œfeel goodโ€ factor early on in the contributor journey.
  • Are there more online workshops that the Make teams can create?
  • Break down the large YouTube tutorial videos into shorter videos.
  • Can we look into how we can improve the badge system for each Make team? And the WP profile page in general.
  • Explore creating events to attract specific types of contributors โ€“ e.g. a design event
  • Make incentives more transparent, make it easy to find out what people did.
  • How can we handle data better? Data can help with the incentives, especially for contributor dayContributor Day Contributor Days are standalone days, frequently held before or after WordCamps but they can also happen at any time. They are events where people get together to work on various areas of https://make.wordpress.org/ There are many teams that people can participate in, each with a different focus. https://2017.us.wordcamp.org/contributor-day/ https://make.wordpress.org/support/handbook/getting-started/getting-started-at-a-contributor-day/., similar to a release squad.

Raw Notes

Continue reading โ†’

#props, #summit, #summit-2023

Community Summit Discussion Notes: Diversity, Equity, Inclusion, and Belonging (DEIB) for all Make Teams

From the session schedule:

This discussion will focus on how the WordPress project can welcome and sustain a diverse pool of contributors to all Make Teams. What are teams currently doing, and what practices can be brought to the whole project? What new practices, resources, support should be introduced?

Perspectives needed: Current and aspiring Make Teams members interested in DEIB.

Facilitator: Birgit Olzem (@coachbirgit)

Notetaker: david wolfpaw (@wolfpaw)

Notetaker: Bigul Malayi (@mbigul)

Notetaker: Taco Verdonschot (@tacoverdo)

Raw Notes:

Topics:

  • What is DEIB? Diversity, Equity, Inclusion, and Belonging.
  • Current state of DEIB in the WordPress project
  • Potential Improvement
  • Collaboration and Support
  • Scope of a DEIB Team?
  • The project today: how the WordPress project can welcome and include a diverse team of makers across all teams.
  • Equity is to ensure that we have the opportunity to give underrepresented groups the same opportunities that already represented groups have.
  • How do we honor the very best of this community? How do we bring people in and feel as welcome and included in our spaces as possible? What can we do to address things that prevent that from happening?
  • We would like members of this community to reflect how diversity in the world exists in the many local communities within our global community.
  • We want to have a diverse mindset
  • Belonging is a new word as part of the acronym. It makes me think of the premise of this discussion: sustain. It is great to have belonging because while we can make this community open, how do we ensure that their needs are continued to be met while as part of this community. I believe that Belonging is representative of that goal. Not only surface things but being able to sustain your presence there.
  • A group of four of us outside noted that we were all from four separate continents. The WordPress community can be an example of making the world more open and peaceful, and bringing the dream of open sourceOpen Source Open Source denotes software for which the original source code is made freely available and may be redistributed and modified. Open Source **must be** delivered via a licensing model, see GPL. to things like politics. I fell in love with the WP community years ago because of that.
  • When we talk about DEIB we have to talk about what the barriers of access for different people. Some of us do not have as much ability to easily access spaces for different reasons. The access for everybody is not the same, and e have to look at that and consider how we individually provide accessibilityAccessibility Accessibility (commonly shortened to a11y) refers to the design of products, devices, services, or environments for people with disabilities. The concept of accessible design ensures both โ€œdirect accessโ€ (i.e. unassisted) and โ€œindirect accessโ€ meaning compatibility with a personโ€™s assistive technology (for example, computer screen readers). (https://en.wikipedia.org/wiki/Accessibility). We also acknowledge that it is not free to do this, for instance adding ramps. We have to invest resources, not just human, but financial, to ensure that events are accessible to everyone, through things like sponsorships and financial support and reaching out to underrepresented groups.
  • Diversity is special to us. India is a land of languages. Different languages, culture, food. The WordPress community is an ecosystem that has allowed many people to come and contribute. There is a communication issue but discussing this will help the community to learn and improve.
  • Seconding that Belonging is important. It is one thing to have DEI, but Belonging brings it full circle.
  • This community is very open. Some people do not know if they will have a place in the WP community and it is great to show that everyone can belong here. I can do what I do here without being judged by my background or what I look like.
  • I want to acknowledge that we have come a long way in this community. Sometimes it is easy to say, โ€œweโ€™ve done it, weโ€™ve created a spaceโ€, but as a community what we havenโ€™t quite done yet is have some of the invisible inclusions. We need to be honest about where we are and arenโ€™t inclusive yet. We donโ€™t want people to have to share their invisible inclusion, but be able to show up and already have space for them. Whatever person you see in front of you, you should not judge their ability or situation.
  • I grew up in India and lived my adult life in the US. I worked in the corporate world before WP, and sometimes I was the only female among white, male developers. It was hard to get that sense of belonging there. I am generally a quiet person, and for folks who are quieter and introverts you donโ€™t feel as left out in the WordPress community. People welcome you and it is very different between this community and the corporate world.
  • We have a variety of diversity, inclduing people from many countries coming here, and finding it enjoyable. It gives me hope because I have been in other technology communities as the lone woman and designer in a room of developers who are men. WordPress has many things to be improved, as any other community. But this community gives me the feeling that things can be changed. I asked a question and it became a team. WordPress has the ability to evolve and improve, and there is an opportunity to make changes that can be little or make great, big things.
  • I love to hear the positive stories about where we are, but for me the diversity and inclusion part is about who is not in this room, and who is not at a WordCampWordCamp WordCamps are casual, locally-organized conferences covering everything related to WordPress. They're one of the places where the WordPress community comes together to teach one another what theyโ€™ve learned throughout the year and share the joy. Learn more.. Someone posted yesterday that they do not feel welcome or safe at WordCamps. We should not ignore this and despite how far weโ€™ve come and how diverse the group is, we cannot stop realizing that there is so much more work to do before everyone feels welcome.
  • What is our status in diversity, not only on events, but within Make team collaborations. Where are the differences between the global and local Make teams, and do you see any interference or points.
  • Local communities are disconnected from Make itself. It is a challenge to introduce a local community to what we do as the WordPress project. A lot of people at local Meetups are seeking help, and a majority of the time it is walking them through a problem, not introducing them to what the WordPress volunteer project does. It creates a sgnificant challenge in introducing more people to the WordPress project.
  • If we are talking about Diversity and Inclusion, we have to talk about it in the MeetupMeetup All local/regional gatherings that are officially a part of the WordPress world but are not WordCamps are organized through https://www.meetup.com/. A meetup is typically a chance for local WordPress users to get together and share new ideas and seek help from one another. Searching for โ€˜WordPressโ€™ on meetup.com will help you find options in your area. community. How do leaders include you, how safe do you feel, and how do they ensure that you return because you feel welcome and safe enough. If you return over time you will learn about the Community and Make teams.
  • How do we handle bad actors in and outside of the community?
  • One of the significant barriers of having people involved is the language barrier. A lot of the Make pages are only in English, and a lot of people cannot read English. Polyglots cannot increase participation in the project because of the language barrier. Many people who donโ€™t speak English do not feel comfortable reaching out about getting involved. How do we get the non-English community feel more welcome to get involved.
  • Translation tools have been very helpful for me to get involved as a non-English speaker
  • WordPress is very open to join, but it is hard to stay for some people. The belonging is not there for everybody. WordPress a toxic positivity problem. We try to make narratives to change minds to get people who are prejudiced to be involved. There are people who cannot be here because their abusers are here. I do not feel safe at conferences where I have spoken out about racism, sexism, and homophobia. It got bad enough that if some people have not stood up for me I would not still be here. How do we do that for everybody? I am one person who stayed, but there are people leaving and losing diversity because people are scared. When people do things and make mistakes we should do something, and we cannot let bad actors blossom in the community. They are not even the best of the community. We have to be strong and speak up but it should not be on us to do so. People donโ€™t want to be calling out their friends, but you should be the one doing so, as you have a better chance of changing them than a stranger. We are a global community. When it is positive it should be global, and when it is negative we should be global.
  • Where does the Code of Conduct apply, and where doesnโ€™t it? Where can we apply things and where can we not? As a community, people can come out and do things, but where as WordPress can we come out and regulate and mandate, and where do we have influence? We have a lot of issues because of this.
  • I am new to WordPress and I am more of an observer. It is a hard place to get more diverse. Unfortunately the people who run the events can take over the conversation sometimes. As an educator I want to make sure that you are included and will try to call you to come into the conversation to ensure that you are heard. It is ok if you come and are lurking but we have people who tend to take over conversations and ensuring that we introduce ourselves to people to get them involved.
  • I have tried getting involved in some teams but onboarding is hard, and it took time to build my confidence to speak up a bit more. Everything is a learning moment. We should be learning every day to be better and support people around us.
  • Instead of organizing a Meetup sometimes we will do things like have a coffee chat or at a sponsor office. Sometimes instead of having a session we will just have talks so that people can be part of a group and we try to bring in newcomers. Most of the people coming to Meetups are coming for their own personal goals. We will try to accommodate them so that they return for the next Meetup and next event. We tell people that if you are attending a Meetup you are a part of the community. We tell people that you do not have to think that you have to be a programmer to be a contributor to an open source project. We tell people to come, write documentation, translate a few strings, post a video. We want people to feel safe to be part of the community. We also have events like parties, and organize in a WhatsApp group. This is going good. We want to have different contributor days, for specific groups and types of contributions, like coreCore Core is the set of software required to run WordPress. The Core Development Team builds WordPress. one day, and documentation another.
  • How do we deal with something that happens when someone is being intolerant? Should we ask them not to come
  • I have held events where we have threatened to be sued. We have to take someoneโ€™s free speech into consideration, and there is a fine line that you have to draw. You donโ€™t want to position yourself where you lose everything when someone pushes the right buttons. You can speak up and say that you donโ€™t feel comfortable, but to tell someone โ€œleaveโ€ is a very slippery slope. It is hard to keep ourselves in a way that we do not have to deal with legal issues.
  • We have had issues with someone at our events who had made physical threats to members of our team, in part because of our marginalized status. We already had issues with this person and WordCamp CentralWordCamp Central Website for all WordCamp activities globally. https://central.wordcamp.org includes a list of upcoming and past camp with links to each. was aware of them. But it took too many meetings, one-on-ones and finally having threats made in a written format that could be shared before something was done.
  • There is a lot of talk about regulation of social media right now for how it influences children. It is hard to see when it is something that you were not born into to see how that works. The current political climate is how we have had a presidency that for four years folks emboldened to say whatever they wanted to say. Before what was unacceptable to say, or only said behind an avatarAvatar An avatar is an image or illustration that specifically refers to a character that represents an online user. Itโ€™s usually a square box that appears next to the userโ€™s name., is no longer unacceptable to say. It now becomes legally ok to say things. There are other parts of the world where there are other similar political issues.
  • Some people engage and organize online, and some people do so via their local communities.
  • The world has a variety of different laws, but we have to tailor based on what some parts of the world define for ourselves, such as GDPR in the EU, and their position making us shift accordingly. Depending on where you are in the world you may not have those checks and balances. There are a lot of things that I see about where you are breaking the law. We donโ€™t just have to deal with various cultures, but also with various legalities around the world.
  • There was a member in our community who wanted sign language interpreters and it had to be with a specific company. This person was very vocally threatening with me about it. I had to have conversations with Central about how to handle it, because they can handle the legality but myself as an individual I cannot handle that.
  • When we look at someone we cannot tell if they are all seeing the same things to consider as we are.
  • The biggest thing that I wanted to bring into the conversation was the idea of community responsibility. Not just what the Community team does about bad actors, but what we as community members do. Thereโ€™s a level of respect, curiosity, and response that I think is a default in WordPress community interactions. One of the strengths that we have as part of a diverse community is that we can continually learn from people who have different backgrounds and experiences. If we are not growing and adjusting we are not learning. The community has grown tremendously in accepting others, but we are going to see those bad actors. What can we do as a community but also individually in doing something about those bad actors.
  • If you want to make people feel like they belonging, what do we as a community do about bad actors? We cannot just let it go. Personally I would not feel that I belong and feel relaxed in an environment where I do not feel like a human being. We need to do things to protect the community in our Code of Conduct.
  • We could come up with a digital policy for the Code of Conduct for how people interact digitally around the community.
  • Your freedom does not allow you to interfere with other peopleโ€™s freedoms.
  • Punishment could be applied for specific infractions, and what people can do, for instance being banned from events for a specific timeframe.
  • We had an incident a few years ago where someone had to be banned for a year and is not going to be an organizer when brought back.
  • Respect others. It is not ok to attack other people online.
  • We do have a community-wide Code of Conduct that does address both in-person community spaces, and online community spaces as well. It is a specific scope. Conversations on social media can become hostile and they are outside of what we consider the core of where we participate. It is challenging to consider where we can have influence from a community support perspective.
  • We have been building out this Code of Conduct as well as an Incident Response team. There is a lot that goes into reaching out to people and supporting community members as best we can. If there are edits that we want to make, we can improve it.
  • Toxic Positivity It is already big that we are talking about it, but some people have to realize that a conversation about diversity an a willingness to improve is important and not making it look like it is a fairy tale.
  • I see someone with an opinion that I absolutely do not appreciate, and is hurtful and wrong, and I see them being scolded at and attacked online by people trying to defend inclusion. It was very much counterproductive, while responses from someone saying that they want to help and educate was taken positively and agreed upon. If there is a chance to educate someone and there is a chance to do something about that and specific people donโ€™t always have to be defending, there are ways to keep people involved and try first to have conversations with someone to show why their position is wrong and hurtful.
  • There was an incident of racism in the community and I had to talk to people that I considered friends and I thought that weโ€™d had an understanding. But they flipped and called the reporters liars, and the incident response team stepped in and helped, but not a lot of people know about them. We found out that the person had multiple violations already. Luckily we had evidence of what these people did.
  • People can be educated and people make mistakes. But you have to be willing in good faith and honesty to take that help. The Incident Response team will step in and help, but why did it have to get to that? How can we stop it from getting to that point where people are on their fourth or fifth chances.
  • We donโ€™t always know the right action if it is not your exclusion. Lots of instances that we are seeing time and time again where people who are marginalized have to stand up for themselves and be the ones to educate, and that is wrong. The people who are being attacked should not have to do the work, and those of us who are privileged should be stepping up, going on a quest for education, learning what support is needed, and offering it.
  • Exclusions impact greatly in a range of spaces outside of just Meetups and WordPress. Tokenism does not help in those spaces. This has happened because of a scarcity in the community spaces and I do not want that to happen.
  • Doing incident reports is one of the hardest jobs. If you love the community and have to see the not so great aspects of the community, it is hard to see. We nee
  • The amount of support that we can directly provide is limited legally, but as people we still care and want to help. Where we can help is collaborating with incident responders for knowledge share to offer support.
  • What can we do in our work to make active contributors feel seen, heard, and belonging?
  • One thing that has been done for regional conferences of a different open source project is having people specifically available both online and in person at smaller events to help with incident response. There are more people present who are not just organizers to respond to attendees in that space. We tried getting people with varied experiences. We have a response playbook that is public for events that we use when an incident occurs at the events. After the event we summarize and anonymize all of the incidents that occurred and what was done about them and publish it for transparency.
  • What would it take to proactively make events and other contributions safe for people? There are different barriers for different people and we can only know about what challenges we are facing ourselves. As much as some of us may want to contribute to events, we cannot take on certain roles. We could ask community members to fill a form to proactively address issues that they may have, to ensure that we are proactively being welcoming to those people.
  • Letting people know how they can feel going to an event, such as a tech event as an older woman who is not a developer.
  • Amplifying incident response teams. A lot of people donโ€™t know who to go to when there are problems, with mediating, helping with people who made mistakes and want to learn, etc
  • Is there a way that we can start learning laws from different parts of the world to solve some of our challenges with a response team and education. The Incident Response team has some access to the legal team for Automattic pro-bono
  • An idea is to create advocacy and ally workshops to educate the rest of the community as to what that entails.
  • We have a Code of Conduct, but if we create a DEIB statement that says something along the lines of if you are part of a marginalized group, whether visible or invisible, you are welcome. If you
  • Three suggestions: making the language more inviting on bringing forth accessibility needs for events. Currently the form for WordCamp tickets asks you to list accessibility needs, but does not invite people who may not feel emboldened to share that those needs will be heard and a good faith effort will be made to address them. Second, trying to be transparent where possible what the limitations of a Code of Conduct would be, for things like legal reasons. Third suggestion, ensuring that a transparency report is published after events to address issues that came up, to avoid toxic positivity and ensuring that there is a bit less second and third hand reporting.
  • There is an organization called CHAOSS (chaoss.community) to help with open source groups, including a knowledge base with metrics around public health and safety. They have a badging system that linux events are required to go through to organize.
  • We asked people with experience organizing events to put some of that experience and ideas on things that went right and wrong in a document for others to review. Having that documentation will help others to get ideas and practical knowledge on how to improve events. My idea is to create a group around having this institutional knowledge available as a resource.
  • The pandemic gave accessibility to Meetups in an interesting ways. There are no Meetups near me, and it is hardly the most remote place. We need to create an online experience as much as possible. If you have a Meetup and can stream it and share it, please do that.
  • We have an aging contributor pool and we need to think about how to expand it to include younger contributors.
  • We need to address other things beyond just community events, such as having onboarding available in multiple accessible formats, and they are not yet. If something is available in only one format, we need to make sure that they are available in other formats to ensure that we have different contributors eventually.
  • We could publish a menu guide at WordCamps to ensure that people can attend an event and ensure that everyone has some form of food that is protein for them. We cannot expect all organizers to know what fits for a vegan or gluten free diet as an example. We could include a template for adding menus on WordCamp sites.
  • I think that we can start with something simple and concrete for how individuals can contribute.
  • One thing that we talked about is what happens when people cause bad situations but we havenโ€™t talked about what happens when team leads are the ones that are causing problems. When someone in leadership makes disparaging comments I have to decide to ignore it or tell people to try to talk about people in different power dynamics.
  • There should be a separate process for project leadership to address power dynamics. Itโ€™s a whole different way to be held accountable. It shouldnโ€™t just be holding them accountable, but requiring that they go through extra education, to ensure that they know a bit more.
  • We can look to other organizations that have had to deal with things done by higher ups, and see what they have published and how they have solved problems. For instance, in the Drupal project.
  • The WordPress project intentionally keeps ticket prices as low as possible to make events accessble, and we donโ€™t cut things like captioning when the budgets donโ€™t work. We need to share the intention about how we spend our funds to ensure that sponsors see that and
  • Future community summits could have captioning to help when people cannot as easily hear speakers. We need people to speak slowly and project and not cross-talk. Can these be part of the guidelines of events, and add specificity.
  • As a teacher, a suggestion is that we can incorporate language like, โ€œouchโ€ to say when people say something harmful and stopping to address it. Or โ€œelmoโ€ to indicate โ€œeverybody, letโ€™s move onโ€ when someone is going on for too long.
  • One thing that Iโ€™ve heard over and over is that, โ€œthey should already knowโ€ for things that things that we assume that people should know, but not everyone knows. I would rather that more is put in the handbook even if we think that people should know them, so that we arenโ€™t put in the position of having to ask uncomfortable questions.
  • Sometimes it is hard to be the person to step up and say something even as an organizer. If you are an organizer, try to recognize when people are having issues or seeing an issue and stepping up on their behalf.
  • There is a dedicated slackSlack Slack is a Collaborative Group Chat Platform https://slack.com/. The WordPress community has its own Slack Channel at https://make.wordpress.org/chat/. channel, #deib-working-group on the Making WordPress Slack
  • How do we honor the very best of our community? What can we do to address the things that prevent that from happening.ย 
  • Belonging is a new word to this acronym. Itโ€™s great to have belonging here. Because once we invited people in, how do we sustain their presence. How do we make them want to be here?
  • The WP community can be an example for the world, as we are ahead of the curve in bringing people together.
  • The WP community has never made me feel uncomfortable or unwelcome, which is a first given many communities Iโ€™ve been part of. However, DEIB is a never-ending project, because thereโ€™s always more to improve.ย 
  • When talking about DEIB we also have to think about barriers. Access for everyone isnโ€™t the same. And we need to acknowledge that people can be in the majority in one aspect, but in a minority in another way.ย 
  • India is a land of variety. Different cultures, different languages, different foods. The WP community is a kind of ecosystem. Itโ€™s adopted many people. Everyone can come in and contribute.ย 
  • This community is a very open community. Thereโ€™s a place for everyone in our community. I feel I can do what I do, and be who I am in this community.
  • What we havenโ€™t quite done yet in this community is pay attention to invisible disabilities or needs.ย 
  • We need everybody here.ย 
  • We should think beyond these flagship events. Where do we see the state of our online community? Whatโ€™s the state of our local communities?
  • Local communities are disconnected from Make itself. As a meetup organizer, I see that many attendees are beginners in WP. Theyโ€™re not even aware thereโ€™s a global WP community. Not everyone organizing events is aware theyโ€™re then part of a team.
  • If weโ€™re touching about D&I, we have to talk about meetups and how weโ€™re supporting meetup organizers integrate people into those local communities.ย 
  • Part of DEIB means making the WP community slightly less welcome to those who are not open to DEIB. So how we deal with bad actors?
  • I want to echo the disconnect between local communities and the Make project. One of the challenges there is the language. Not everyone can speak English. This language barrier brings up the next barrier.ย 
  • WordPress is very open to join, but itโ€™s hard to stay for some. The belonging is not there. If something happens, we try to out-positive it. But we seem to think that with a Disney-movie ending, it will all be fine. But in reality, itโ€™s up to the same people over and over again to fight this fight.
  • When thereโ€™s a bad actor, yes we need to educate them, but maybe we also need. People are afraid to call out their friends, but that is whatโ€™s needed to make things better.
  • Where does the COC apply, and where does it not? Where can regulate, and where can we only influence?
  • Everything is a learning moment. We should be working every day to improve ourselves.ย 
  • Most people who come to our meetups are mainly looking for help. Most of them are in a learning curve. So oftentimes we organize meetups that a basically a chit-chat, instead of doing a session. We also continue to tell people they donโ€™t have to be a programmer.ย 
  • When someone is crossing a border about inclusivity, is telling them not to come to an event non-inclusive?
  • [General response] No.ย 
  • As an organizer, there was a prior attendee who made me and other feel physically unsafe. That made organizing very difficult. It was challenging at the time to get the support we felt we needed. It was disheartening that it came to the point where it needed to escalate to a physical threat via email before action was taken.
  • We have generations that didnโ€™t spend the majority of their life on social media. Itโ€™s important to recognize that there is a generation that is completely influenced by social media.
  • We are in a situation where things that in the past were only said from behind an anonymous avatar online are now said in-person, due to changes in the cultural and political climate.
  • Weโ€™re a world-wide community, but weโ€™re not dealing with the same laws everywhere. So beyond different cultures, weโ€™re also facing different legal structures.
  • If you want to make the community more diverse, we have to respond to bad actors. We canโ€™t let it go. We need to protect the people we want to keep in the community.
  • We do have a community code of conduct, that addresses both online and offline parts of our community. Sometimes itโ€™s outside of the scope of what we (WP) can regulate. WP does have an Incident Response Team thatโ€™s handling COC violations within WordPress. make.wordpress.orgWordPress.org The community site where WordPress code is created and shared by the users. This is where you can download the source code for WordPress core, plugins and themes as well as the central location for community conversations and organization. https://wordpress.org//community/handbook/code-of-conduct/
  • Create more awareness for the IRT.ย 
  • Create list of things that make people feel unsafe/unwelcome.ย 
  • Create an inclusivity statement that we publish in our community to help people understand expected behavior.ย 
  • Create a (non-exhaustive) overview of the spaces where we can interact.
  • Have a transparency report from the eventโ€™s IRT in the post-event wrap up.
  • Learn from https://chaoss.community/.
  • Create resources to do better. For example an example vegan menu to help local organizers get that right.
  • Share the list of names of people who are on the IRT, to make clear to the community that itโ€™s not just Automatticians. People from around the world are included and theyโ€™ve had โ€œformalโ€ training.

In the first half of the session we have mainly discussed the following.ย 

  • What is DEIB
  • Current state of DEIB
  • Potential improvementย 
  • Collaboration & Support
  • Scope of a DEIB Teamย ย 

Key Points came out in the discussions are

  • WordPressโ€™s growth continues. We are a very big team now.ย 
  • WordPress is a never ending projectย 
  • The WordPress ecosystem accommodates thousands of people from different backgrounds(like nationalities, languages, religion, cultures, politics, beliefs etc..)ย 
  • The Make WordPress project is also vast and has multiple tracks.ย 
  • We are a very diversified community.ย 
  • Because of diversity our each local team will be different & has many barriersย 
  • Diversity will be different for each local teamย 
  • Our community represents multiple interests
  • WordPress is very open to join, we have to maintain thatย 
  • Therefore we need a team to take care of both
  • The biggest challenge is we have to make sure the community accessible to allย 
  • The next generation is coming to the stage now. So we have to make sure a smooth generation changeย ย 
  • We have to welcome & open new people & ideas alwaysย 
  • The biggest challenge is accommodating new people & transforming them as contributorsย 
  • So the Sustainability of contributors mattersย 
  • Transparency in all actions are must for itย 
  • ย We have to consider the feelings of new & existing people
  • The community should be open to all and there should be any judgement based on their backgroundย 
  • We have work on the documentations to keep the resource live & easy accessibleย 
  • Because of language barriers we can consider of translating documentationsย 
  • Each one should be considered equally(not matter of gender & race)ย 
  • The local community should be connected with global communityย 
  • Meetup Organiser should make sure everyoneโ€™s voice is heardย 
  • Document the meetups if possibleย 
  • Everything is a learning moment. So support the people & their ideas around with kindness and toleranceย 
  • We are living in a era of extremism so we have to consider the people with equalityย 
  • It will be great if we can consider digital code of conduct. It will be more helpful for the people
  • We can also regulate the code of conduct oftenย 
  • We are from different continents & countries. So may have to consider the localization of the code of conduct with extra attributes/termsย ย ย 
  • We should start to train the people about the code of conductย 
  • Clear & easy guidelines for the newcomers speciallyย 
  • Global & local team to monitor and take actions if any incident happensย 

Actionable Items to improve DEIBย 

  • All should feel as more welcomed
  • Events should be more aligned to DEIB
  • Looking for make our work(contribution) more sustainableย 
  • Raise more awareness & committee/team for code of conduct
  • We have to take care of disabled people, their requirements will be different. Encourage participation & contribution from them
  • Keeping an ongoing list for people from all backgrounds(Organiser, Volunteers & participants). It will welcome & encourage more people
  • Local communities face different legal issues. A legal handbook to refer for the working group
  • Create advocacy and allyship. Classes for organisersย 
  • Educate, meetup members & conduct workshops.ย 
  • Transparency & inclusivity statement
  • Have a form people can fill our(even anonymously)ย 
  • Ageing(balance between ageing contributor & new one)
  • Incorporate wording that lets people to know that it is okay to ask for accommodation on formย 
  • Transparency around what can & cannot be doneย 
  • Transparency reports around issues to clarify and avoid rumoursย 
  • Publish official responses
  • Checkout documents the other organisations have already created and adjust accordingly. Example for those documents are Drupal & https://chaoss.community/ย 
  • Create online experience as much as possibleย 
  • Make information/meetups available through more than one formatย 
  • A menu guide for WordCampsย 
  • We can be friendlier & more open as a community. Proactive with other community members alsoย 
  • A separate process for the higher leadership
  • Training for the leadership
  • An open forum to speak, report regardless of the level of leadershipย 
  • Setup as an organiser
  • A WordPress Languageย 
  • Add as much info as needed more to the handbookย 
  • WordPress events are budget events. We have to keep the sponsor aware about thisย 
  • Budget Transparencyย 
  • Text capture in next community summitย 

#summit, #summit-2023

Community Summit Discussion Notes: Improving maintenance of older default themes

Title of Session: Improving maintenance of older default themes

Facilitator: @desrosj

Notetaker 1: @mikachan

Notetaker 2: @zoonini

From the session schedule:

Recently, there was a proposal to retire some old default themes. In response concerns were raised around how to do so. This discussion aims to explore how to maintain older default themes in more sustainable, streamlined methods.

Key Points

  • Concerns raised around breaking the promise of supporting all default themes forever, just like we do for CoreCore Core is the set of software required to run WordPress. The Core Development Team builds WordPress..
  • Can we write an underlying framework to help support all themes?
    • Theyโ€™re all so different so may be difficult to build a framework to support all of them. It could be a lot of work.
  • Older themes are an educational resource for theme developers. By maintaining older themes we are educating developers on how to update their own themes.
  • The burden falls on the Core team to maintain themes. Original theme authors often get re-assigned or leave the project.
    • How can we help spread the workload?
    • Can we onboard more people to maintain themes?
    • We have already tried having a default theme maintenance team. This has previously been a burden; 20xx themes are a burden to maintain.ย 
  • Why is there only a default theme lead for the last version of the year?
    • Why not each release so updates can be bundled in each release?ย 
    • Used to have a Theme Wrangler for each release but this dropped off.
  • More docs needed for default themes.
  • Using the default theme to showcase new features makes it difficult for backwards compatibility.
  • Does it have the same impact if we make all default themes blockBlock Block is the abstract term used to describe units of markup that, composed together, form the content or layout of a webpage using the WordPress editor. The idea combines concepts of what in the past may have achieved with shortcodes, custom HTML, and embed discovery into a single consistent API and user experience. themes?
  • Is there a world where we could make all default themes as light as possible?
  • Default themes can be updated outside of the release cycle. Could we introduce a regular cycle of updating default themes? Theme cycle vs release cycle
  • What about designing a method of testing older themes for each release?

Action Items/Next Steps:

  • Explore moving default themes to GithubGitHub GitHub is a website that offers online implementation of git repositories that can easily be shared, copied and modified by other developers. Public repositories are free to host, private repositories require a paid subscription. GitHub introduced the concept of the โ€˜pull requestโ€™ where code changes done in branches by contributors can be reviewed and discussed before being merged be the repository owner. https://github.com/ (with sync to SVNSVN Apache Subversion (often abbreviated SVN, after its command name svn) is a software versioning and revision control system. Software developers use Subversion to maintain current and historical versions of files such as source code, web pages, and documentation. Its goal is to be a mostly compatible successor to the widely used Concurrent Versions System (CVS). WordPress core and the wordpress.org released code are all centrally managed through SVN. https://subversion.apache.org/.)
    • Pick the most critical issues from tracTrac Trac is the place where contributors create issues for bugs or feature requests much like GitHub.https://core.trac.wordpress.org/. to move over
  • Consider having a Theme Wrangler for every release
  • Explore creating style variations and patterns based on past default themes, as a way to blockify the older themes
  • Explore setting up visual regression testing for default themes
  • How do we improve the feedback loopLoop The Loop is PHP code used by WordPress to display posts. Using The Loop, WordPress processes each post to be displayed on the current page, and formats it according to how it matches specified criteria within The Loop tags. Any HTML or PHP code in the Loop will be processed on each post. https://codex.wordpress.org/The_Loop. from people building themes in GB?
  • Improve default theme docs

Raw Notes

Continue reading โ†’

#summit, #summit-2023

Community Summit Discussion Notes: Refining Five for the Future For a Robust WordPress Community

From the session schedule:

The Five for the Future (โ€œ5ftFโ€) program can help ensure the long term health of WordPressโ€™ contributor pipeline. To make 5ftF as effective as possible, strong participation from 5ftF companies and project-wide understanding of Make Team needs and priorities is required. As such, this discussion will focus on two related topics:

  1. How we can more readily identify priority needs and opportunities and match them to 5ftF contributors.
  2. How to incentivize and facilitate further participation to the 5ftF program.

Facilitator: Jeff Paul (@jeffpaul)

Notetaker: Kim Coleman (@kimannwall)

Continue reading โ†’

#summit, #summit-2023

Community Summit Discussion Notes: Building trust in WordPress CMS and plugin security

Community Summit Discussion Notes

Title of Session: Building trust in WordPress CMS and pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party security

Facilitator: Peter Wilson

Notetaker 1: Ryan McCue

Notetaker 2: Weston Ruter

Notetaker 3: Jason Coleman

Key Points

  • Communication of security practices:
    • Organization
      • The security page on WordPress.org needs to be refreshed with a clearer message โ€“ this will benefit WordPress from an external perspective, and can be a jumping off point internally too
      • This can point out to the various handbooks (security, plugin, theme, hosting)
      • The whitepaper is also heavily out-of-date and needs refreshing
    • WordPress as a project should be โ€œowningโ€ the security conversation, rather than leaving to third-parties
    • Documentation can be improved, but is โ€œpassiveโ€ โ€“ active communication (i.e. marketing) must also take place. Other teams (docs and marketing) are able and willing to help if the raw communication is available, and can share some of this communication burden.
  • Responsibility and ecosystem:
    • WordPress decided to provide plugin functionality, so must take responsibility for the security of it โ€“ we cannot say that this is the ecosystemโ€™s problem alone to solve
    • The ecosystem is broader than just the .org repository, so security cannot be โ€œcontrolledโ€ through the repository alone
      • Tools such as scanners could potentially be built into WordPress itself, mirroring operating system virus scanners eg
      • A โ€œsafe modeโ€ could be added to disable all plugins (eg), but this is often one of the first things to be bypassed โ€“ external tools (such as those operated by hosts) are likely to be a safer way to achieve this
    • Tools are available to the ecosystem (autoupdates via the plugin team, eg) but awareness of these is low. These are available for authors of non-trivial usage plugins (e.g. something like 20k+ installs would be a workable threshold)
    • Documentation exists around how to write secure code, but there isnโ€™t sufficient or sufficiently-known documentation on procedure of how to deal with vulnerabilities, how to issue security releases, and how to communicate
      • Make it clear to ecosystem authors that vulnerabilities will happen, and destigmatize the process
      • A โ€œwhat to do if your plugin has a vulnerabilityโ€ guide could bring this information together
    • Documentation needs to be clearly findable and approachable for the ecosystem, and can tie in to the refreshed page

Action Items/Next Steps:

  • Refresh the .org security page
  • Refresh the security whitepaper
  • Write documentation on procedure for dealing with vulnerabilities

Raw Notes

Continue reading โ†’

#security, #summit, #summit-2023, #wpscan

Community Summit Discussion Notes: How does the Make Team ecosystem work and how are we connected?

From the schedule session:

There are 22 Make Teams (and counting!) that build WordPress. Each team has itโ€™s mandate and priorities, and are connected by the overarching purpose of moving WordPress forward. For contributors working on one team, it can be easy to lose sight of the broader project and other teams, or see how your teamโ€™s work fits in. This discussion will explore how teams are connected and the impact a team may have on others, with an eye towards growing our collective understanding of the Make WordPress ecosystem as a whole. We will also explore how we can keep growing this collective understanding for all new and current contributors.

Facilitator: Hari Shanker (@harishanker)

Notetaker 1: Emma Sophie Young (@emmaht)

Notetaker 2: Erica Varlese (@evarlese)

Notetaker 3: Taco Verdonschot (@tacoverdo)

Continue reading โ†’

#summit, #summit-2023

Community Summit Discussion Notes: Is Succession Planning Possible in Open Source?

From the session schedule:

Key work for all leaders is investing in the next generation of leadership. This is especially true (yet especially hard) in free and open sourceOpen Source Open Source denotes software for which the original source code is made freely available and may be redistributed and modified. Open Source **must be** delivered via a licensing model, see GPL. software (FOSS), where you see hybrid concerns: not-for-profit/for-profit, volunteer/paid, skilled/unskilled. While our leadership group has expanded, itโ€™s still unclear how to confirm a succession plan (either from an emergent or planned perspective).

Facilitator: Joe McGill (@joemcgill)

Notetaker 1: Kim Coleman (@kimannwall)ย 

Notetaker 2: Isotta Peira (@peiraisotta)

Continue reading โ†’

#summit, #summit-2023