Contribution
ContributorA scoped issue, acceptance criteria, tests and a pull request. No production credentials.
A home for the people who test, review and protect the work. Everyone can propose a change. Shipping it requires independent evidence and authority.
Joining a project, claiming work or completing a task never grants merge access, production credentials or permission to deploy.
A scoped issue, acceptance criteria, tests and a pull request. No production credentials.
Secret scan, dependency audit, type checks, database tests, production build and browser checks on the proposed commit.
Someone other than the author verifies behavior, maintainability, accessibility and acceptance criteria.
Review data access, abuse cases, dependencies and trust boundaries. Auth, database, workflow and release changes require specialist review.
Approve the exact reviewed commit and preview, record rollback and release evidence, then verify production.
Server verification, validated inputs and database access policies are in source. Hosted behavior still requires operator verification.
Known secret patterns, dependency audit, type checks, database tests, build and browser tests. A definition is not a successful run.
Required reviews, protected branches and production approvers must be verified in the providers. No live enforcement status is claimed here.
Security, maintainer and release roles need named, consenting people. This page does not invent a staffed team.
New and experienced contributors follow the same review boundary. Passing tests never substitutes for an independent review.
Real founding work, ready for humans to take over. Roles remain unassigned until someone accepts them.
Give the community an accountable review team before widening release access.
Publish consenting maintainer and security reviewer contacts; document conflicts of interest and coverage; configure protected main with required checks and fresh independent reviews; prove a failing pull request cannot merge; record provider evidence.
Needs: Owner appoints trusted reviewers and approves repository settings.
Demonstrate that untrusted contributions cannot gain authority or ship themselves.
Publish a threat model and reproducible safe tests; prove self-approval and unauthorized completion are rejected; demonstrate stale evidence blocks acceptance; verify that application task completion cannot trigger a production deploy.
Needs: Hosted staging auth; independent review and release controls configured.
Make every release attributable, reviewable and recoverable.
Record source SHA, preview URL, check results and independent approvals; prove unauthorized deployment denied; rehearse rollback in staging; verify the released URL and record an owner-approved production procedure.
Needs: Harness team appointed; hosting release permissions reviewed.