needs-human — this concerns organization roles and privileged access; implementation details that would weaken security should remain private.
Readiness gap
A production assurance framework needs continuity beyond the availability of any one maintainer. Before v1, no single person should be required to:
- review and merge a security-sensitive change;
- publish every PyPI/npm/platform artifact;
- rotate or revoke publication credentials;
- issue a security advisory;
- recover branch protection, package ownership or release automation;
- explain the release and incident-response process from memory.
This is not a request to disclose sensitive access details. It is a request to prove that ownership and recovery are redundant.
Acceptance criteria
needs-human— this concerns organization roles and privileged access; implementation details that would weaken security should remain private.Readiness gap
A production assurance framework needs continuity beyond the availability of any one maintainer. Before v1, no single person should be required to:
This is not a request to disclose sensitive access details. It is a request to prove that ownership and recovery are redundant.
Acceptance criteria
GOVERNANCE.mdorMAINTAINERS.mddefining maintainer roles, decision authority and how maintainers are added or removed.