Issue Description
The project currently lacks a dedicated governance document required for OSSF (Open Source Security Foundation) Best Practices Silver badge compliance.
OSSF Requirement ([governance]):
The project MUST clearly define and document its project governance model (the way it makes decisions, including key roles). (URL required)
Current gaps identified:
| Aspect |
Status |
| Dedicated governance document |
❌ Missing |
| Decision-making process |
❌ Implied but not explicit |
| Key roles and responsibilities |
❌ Partially defined in CODEOWNERS only |
| Dispute resolution process |
❌ Missing |
| Governance model type stated |
❌ Missing |
Proposed deliverables:
-
Create GOVERNANCE.md in repository root with:
- Explicit governance model statement (maintainer-led under Microsoft sponsorship)
- Roles section (Maintainers, Contributors, Reviewers)
- Decision-making process (routine changes, new features, breaking changes, governance changes)
- Dispute resolution procedure
- Process for modifying governance
-
Update cross-references in:
README.md - Add governance link in Legal section
CONTRIBUTING.md - Reference governance for maintainer authority
Acceptance criteria:
Additional Context
Reference: OSSF Best Practices Badge - Governance criterion
Existing partial coverage:
Issue Description
The project currently lacks a dedicated governance document required for OSSF (Open Source Security Foundation) Best Practices Silver badge compliance.
OSSF Requirement ([governance]):
Current gaps identified:
Proposed deliverables:
Create
GOVERNANCE.mdin repository root with:Update cross-references in:
README.md- Add governance link in Legal sectionCONTRIBUTING.md- Reference governance for maintainer authorityAcceptance criteria:
GOVERNANCE.mdexists in repository root with required frontmatterREADME.mdlinks to governance documentCONTRIBUTING.mdreferences governance for decision authoritynpm run lint:md)Additional Context
Reference: OSSF Best Practices Badge - Governance criterion
Existing partial coverage:
@microsoft/edge-ai-core-devas code owners