Skip to main content

Project Governance

Contribute / Project Governance

Use these pages when you are changing how the project is governed, secured, or published.

This section is for policy and maintainer work: SDLC expectations, supply-chain controls, and dependency license rules. It is not the place to start for normal feature work, but it is the right place when you are changing how OpenBao Operator proves trust or manages release risk.

Project governance guides

  1. 01

    Software development lifecycle

    See how planning, implementation, verification, release, and operations map into the project’s secure lifecycle.

    Open
  2. 02

    Supply chain security

    Review provenance, reproducibility, signing, evidence, and release-control expectations.

    Open
  3. 03

    Supply-chain incident response

    Use the maintainer runbook when you need to freeze Actions, suspend release automation, rotate trust roots, or inspect recent publication state.

    Open
  4. 04

    Dependency license policy

    Understand which licenses are allowed for shipped binaries and how the policy is enforced.

    Open

Related maintainer work

Next release documentation

You are reading the unreleased main docs. Use the version menu for the newest published release, or check the release notes for what is already out.

Was this page helpful?

Use Needs work to open a structured GitHub issue for this page. The Yes button only acknowledges the signal locally.