Skip to content

[GH-03] Standardize security, license, contribution, release, and support policies #4

Description

@jaavid

Background

CoreLink is managed as one product across multiple implementation boundaries. This work is owned by .github under EPIC-02.

Problem

The organization does not yet have verified, consistently maintained evidence for this outcome: Standardize security, license, contribution, release, and support policies.

Goal

Standardize security, license, contribution, release, and support policies and make the result the authoritative, reviewable baseline for all affected repositories.

Parent

  • Primary Product Epic: EPIC-02
  • Backlog ID: GH-03

Scope

  • Deliver the stated outcome in .github.
  • Reconcile affected organization policy, product claims, ownership, security, release, documentation and repository maturity.
  • Retain acceptance evidence for the Foundation gate.

Out of Scope

  • Runtime feature implementation in this Issue.
  • Duplicating the product roadmap in repository README files.
  • Presenting scaffolds or planned capability as a supported release.

Acceptance Criteria

  • The outcome is documented or configured in its authoritative location.
  • Affected repositories link to the source of truth instead of copying it.
  • Ownership, review and exception paths are explicit.
  • Security, license, privacy and release impacts are addressed where applicable.
  • The result is validated against at least one real repository workflow.
  • Acceptance evidence is linked and the parent Epic is updated.

Technical Notes

Use organization-wide defaults where inheritance is reliable. Repository-specific exceptions must be minimal and documented. Product maturity claims must distinguish Scaffold, Experimental, Alpha, Beta, Stable and Deprecated.

Dependencies

  • Decision prerequisites: organization license policy and support policy must be explicitly approved; these are governance decisions, not repository implementation blockers.
  • Blocks: GH-04, SDK/package publication work that requires an approved license/support policy, and EPIC-02 Foundation policy acceptance.
  • Cross-repository: Link concrete affected Issues; do not duplicate implementation.
  • Current dependency state: See the CoreLink Product organization Project.

Planning Metadata

  • Type: Technical Task
  • Priority snapshot: P0
  • Product milestone snapshot: Foundation
  • Domains snapshot: security, governance
  • Area snapshot: documentation
  • Complexity: M
  • Created in status: Triage
  • Current status and DRI: See the CoreLink Product organization Project.
  • Intended repository labels: type:technical-task

Definition of Done

  • Acceptance criteria demonstrated.
  • Required reviews and retained evidence pass.
  • Organization and repository links are updated.
  • Security and policy implications are reviewed.
  • Documentation and release notes are updated where applicable.
  • Pull request or configuration change is linked.

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:technical-taskImplementation or engineering enablement work

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions