Repository navigation
Establish maintainer coverage, drift checks and release handover - #52
Merged
Merged
Conversation
This was referenced Oct 2, 2026
Merged
imran-siddique
enabled auto-merge (squash)
October 2, 2026 21:27
satishaakula
approved these changes
Oct 2, 2026
imran-siddique
added a commit
to agentrust-io/agentrust-telemetry
that referenced
this pull request
Oct 2, 2026
Align with the [canonical maintainer coverage rollout](agentrust-io/.github#52). Adds the generated maintainer policy snapshot for the daily coverage audit. Existing CODEOWNERS and branch-review requirements continue to enforce reviews; this repository does not gain a redundant named-review workflow. Primary/backup routing, verified write access and pending capacity/publisher checks are recorded centrally. No access grant or new appointment is claimed. Validation: nine approval-boundary tests passed and all 11 generated snapshots matched the canonical record. Repository CI and independent review remain required.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Routine reviews, ownership and publishing currently depend on separate rosters and personal follow-through. This establishes one canonical coverage record for 11 active repositories, with two non-Imran routing owners per repository and verified write/admin access for all 22 assignments.
Generated maintainer policies read only the reviewed base commit. A first-deployment fallback is restricted to the exact initial base SHA; later missing or invalid policy fails closed. CMCP/CA2A security paths require two distinct current-head human approvals, including renames out of those paths. Independent branch reviews remain required for maintainer-authored routine changes.
The daily read-only audit detects drift in policy, CODEOWNERS and review gates. The handover record separates verified repository access from pending capacity acceptance, specialist-team membership, organization-owner recovery and package/environment access. It defines release operator checks and a seven-day handover with linked review/merge/build evidence. No new maintainer appointment, access grant or governance exception is asserted.
Validation: ten Node boundary tests passed; all 11 generated snapshots matched their canonical policies, owners and gates. Reducing security approvals to one made three tests fail. Consumer rollout PRs update each repository; deployment and private access verification remain pending.
Rollout PRs and remaining verification are tracked in the handover record. Ten PRs have auto-merge enabled; registry requires a normal maintainer merge.