Decision
SightAdapt does not plan or require external legal, trademark, patent, privacy/DPO or medical-device audits. Release and business-risk decisions are made by the responsible maintainer/publisher using repository evidence, public sources and explicit risk acceptance.
Internal review is not legal advice. The project must not claim legal clearance, non-infringement, trademark availability, patent freedom to operate, MDR approval or professional audit.
Implemented governance
docs/legal/LEGAL-RELEASE-GATE.md defines the maintainer review process;
docs/legal/MAINTAINER-RELEASE-REVIEW-TEMPLATE.md defines a reusable internal decision record;
docs/legal/MAINTAINER-RELEASE-REVIEW-0.5.0.50-alpha-2026-07-30.md records the current alpha decision;
- the decision package covers exact artifacts, checksums, SBOM, notices, privacy, contribution provenance, brand risk, intended purpose, patent risk and public claims;
- each risk is accepted, mitigated, excluded or blocking;
- material scope changes trigger a new maintainer review;
- privileged/external-advice storage and external sign-off are no longer project requirements.
Acceptance criteria
Implementation
Decision
SightAdapt does not plan or require external legal, trademark, patent, privacy/DPO or medical-device audits. Release and business-risk decisions are made by the responsible maintainer/publisher using repository evidence, public sources and explicit risk acceptance.
Internal review is not legal advice. The project must not claim legal clearance, non-infringement, trademark availability, patent freedom to operate, MDR approval or professional audit.
Implemented governance
docs/legal/LEGAL-RELEASE-GATE.mddefines the maintainer review process;docs/legal/MAINTAINER-RELEASE-REVIEW-TEMPLATE.mddefines a reusable internal decision record;docs/legal/MAINTAINER-RELEASE-REVIEW-0.5.0.50-alpha-2026-07-30.mdrecords the current alpha decision;Acceptance criteria
Implementation