Skip to content

Establish maintainer coverage, drift checks and release handover - #52

Merged
imran-siddique merged 3 commits into
mainfrom
maintainer-coverage-20261002
Oct 2, 2026
Merged

imran-siddique merged 3 commits into
mainfrom
maintainer-coverage-20261002

Conversation

@imran-siddique

@imran-siddique imran-siddique commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Routine reviews, ownership and publishing currently depend on separate rosters and personal follow-through. This establishes one canonical coverage record for 11 active repositories, with two non-Imran routing owners per repository and verified write/admin access for all 22 assignments.

Generated maintainer policies read only the reviewed base commit. A first-deployment fallback is restricted to the exact initial base SHA; later missing or invalid policy fails closed. CMCP/CA2A security paths require two distinct current-head human approvals, including renames out of those paths. Independent branch reviews remain required for maintainer-authored routine changes.

The daily read-only audit detects drift in policy, CODEOWNERS and review gates. The handover record separates verified repository access from pending capacity acceptance, specialist-team membership, organization-owner recovery and package/environment access. It defines release operator checks and a seven-day handover with linked review/merge/build evidence. No new maintainer appointment, access grant or governance exception is asserted.

Validation: ten Node boundary tests passed; all 11 generated snapshots matched their canonical policies, owners and gates. Reducing security approvals to one made three tests fail. Consumer rollout PRs update each repository; deployment and private access verification remain pending.

Rollout PRs and remaining verification are tracked in the handover record. Ten PRs have auto-merge enabled; registry requires a normal maintainer merge.

@imran-siddique
imran-siddique merged commit e3a7837 into main Oct 2, 2026
4 checks passed
@imran-siddique
imran-siddique deleted the maintainer-coverage-20261002 branch October 2, 2026 21:48
imran-siddique added a commit to agentrust-io/agentrust-telemetry that referenced this pull request Oct 2, 2026
Align with the [canonical maintainer coverage
rollout](agentrust-io/.github#52).

Adds the generated maintainer policy snapshot for the daily coverage
audit. Existing CODEOWNERS and branch-review requirements continue to
enforce reviews; this repository does not gain a redundant named-review
workflow.

Primary/backup routing, verified write access and pending
capacity/publisher checks are recorded centrally. No access grant or new
appointment is claimed. Validation: nine approval-boundary tests passed
and all 11 generated snapshots matched the canonical record. Repository
CI and independent review remain required.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants