Skip to content

docs: update ROADMAP with enterprise adoption milestones (June 2026)#5

Merged
shenxianpeng merged 1 commit into
mainfrom
docs/update-roadmap-2026
May 30, 2026
Merged

docs: update ROADMAP with enterprise adoption milestones (June 2026)#5
shenxianpeng merged 1 commit into
mainfrom
docs/update-roadmap-2026

Conversation

@shenxianpeng
Copy link
Copy Markdown
Contributor

Summary

Updates the ROADMAP based on a community review of the 10 most impactful enterprise adoption features. Key changes:

What's Marked Complete

  • M1 (First Trusted Checkpoint) and M2 (AI-Native Tooling) — completed May 2026
  • Added Enterprise Policy & Compliance Tooling status table showing all production-ready capabilities that were already implemented but not reflected in the roadmap

New Milestones (all targeting 2026)

Milestone Quarter Highlights
M3 — Enterprise Adoption Surface Q3 2026 ods init, adoption mode (observe/warn/enforce), multi-platform CI examples, agent instructions
M4 — Supply Chain & Compliance Bridge Q3–Q4 2026 SLSA evidence bridge, NIST AI RMF / EU AI Act control mapping, evidence module promotion
M5 — Community & Governance Q4 2026 Formal governance, adopters

Mapping to Community Review

The 10 suggestions from the community review and their status:

# Suggestion Status
1 .ods.yaml Policy + profiles ✅ Done — in M2
2 Compliance Report (HTML/JSON/SVG) ✅ Done — in M2
3 PR fix suggestions / Bot comment ✅ Done — in M2
4 AI Disclosure Attestation ✅ Done — in M2
5 Soft-fail / Adoption Mode 📋 → M3
6 GitLab CI / Bitbucket / Jenkins 📋 → M3
7 ods init scaffolding 📋 → M3
8 SLSA Bridge 📋 → M4
9 AI Agent Instructions 📋 → M3
10 NIST/EU AI Act Control Mapping 📋 → M4

Design Decisions

  • Timeline compressed to all-2026 to match aggressive delivery pace
  • "Replacing SLSA" added to Non-Goals with clarification: ODS complements SLSA
  • Agent instructions and ods init added to M3 as high-priority enterprise friction reducers

- Mark M1 and M2 as completed (May 2026)
- Add Enterprise Policy & Compliance Tooling status table
  listing completed capabilities: .ods.yaml profiles,
  compliance report, fix suggestions, AI review records
- Add M3: Enterprise Adoption Surface (Q3 2026)
  - ods init scaffolding command
  - adoption mode (observe/warn/enforce)
  - multi-platform CI examples (GitLab CI, Bitbucket, Jenkins)
  - AI agent instructions (AGENTS.md)
  - L1 modules to Stable
- Add M4: Supply Chain & Compliance Bridge (Q3-Q4 2026)
  - SLSA evidence bridge / JSON mapping
  - NIST AI RMF / EU AI Act control mapping
  - ods-ai-review.json artifact
- Add M5: Community & Governance (Q4 2026)
- Compress timeline: all milestones target 2026
- Clarify ODS complements SLSA in non-goals
@shenxianpeng shenxianpeng merged commit b242a2e into main May 30, 2026
2 checks passed
@shenxianpeng shenxianpeng deleted the docs/update-roadmap-2026 branch May 30, 2026 04:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant