Problem
This public v1 project lacks the maintainer and release-governance baseline expected by enterprise adopters: named ownership, standard contribution entry points, and recorded protection expectations.
Scope
- Add
CODEOWNERS for source, contracts, security-sensitive areas, workflows, and release assets.
- Add pull-request and issue templates that capture compatibility, security, migration, and operational impact.
- Document required checks, review expectations, protected default-branch/release settings, and supported disclosure path.
- Keep this governance contract aligned with the supply-chain release issue rather than duplicating its implementation.
Acceptance criteria
- A contributor can identify owners and submit a reviewable change with compatibility and security context.
- Maintainers can demonstrate the expected branch and release protection baseline.
Problem
This public v1 project lacks the maintainer and release-governance baseline expected by enterprise adopters: named ownership, standard contribution entry points, and recorded protection expectations.
Scope
CODEOWNERSfor source, contracts, security-sensitive areas, workflows, and release assets.Acceptance criteria