Project Governance
Contribute / Project Governance
Use these pages when you are changing how the project is governed, secured, or published.
This section is for policy and maintainer work: SDLC expectations, supply-chain controls, and dependency license rules. It is not the place to start for normal feature work, but it is the right place when you are changing how OpenBao Operator proves trust or manages release risk.
Project governance guides
- 01Open
Software development lifecycle
See how planning, implementation, verification, release, and operations map into the project’s secure lifecycle.
- 02Open
Supply chain security
Review provenance, reproducibility, signing, evidence, and release-control expectations.
- 03Open
Supply-chain incident response
Use the maintainer runbook when you need to freeze Actions, suspend release automation, rotate trust roots, or inspect recent publication state.
- 04Open
Dependency license policy
Understand which licenses are allowed for shipped binaries and how the policy is enforced.
Related maintainer work
You are reading the unreleased main docs. Use the version menu for the newest published release, or check the release notes for what is already out.
Was this page helpful?
Use Needs work to open a structured GitHub issue for this page. The Yes button only acknowledges the signal locally.