Skip to content

[Legal Governance] Record maintainer-owned release-risk decisions #93

Description

@KeyffMS

Decision

SightAdapt does not plan or require external legal, trademark, patent, privacy/DPO or medical-device audits. Release and business-risk decisions are made by the responsible maintainer/publisher using repository evidence, public sources and explicit risk acceptance.

Internal review is not legal advice. The project must not claim legal clearance, non-infringement, trademark availability, patent freedom to operate, MDR approval or professional audit.

Implemented governance

  • docs/legal/LEGAL-RELEASE-GATE.md defines the maintainer review process;
  • docs/legal/MAINTAINER-RELEASE-REVIEW-TEMPLATE.md defines a reusable internal decision record;
  • docs/legal/MAINTAINER-RELEASE-REVIEW-0.5.0.50-alpha-2026-07-30.md records the current alpha decision;
  • the decision package covers exact artifacts, checksums, SBOM, notices, privacy, contribution provenance, brand risk, intended purpose, patent risk and public claims;
  • each risk is accepted, mitigated, excluded or blocking;
  • material scope changes trigger a new maintainer review;
  • privileged/external-advice storage and external sign-off are no longer project requirements.

Acceptance criteria

  • Identify the responsible publisher and decision owner.
  • Identify the current territories, channels, revenue/support model and users.
  • Define the exact evidence package for a release decision.
  • Include .NET redistribution, dependencies, SBOM, notices and licenses.
  • Include trademark/name/logo risk and monitoring.
  • Include intended-purpose and medical-claims boundaries.
  • Include internal patent-risk treatment.
  • Include privacy and support-data handling.
  • Include contribution provenance and DCO evidence.
  • Record known, accepted, mitigated and excluded risks.
  • Add a reusable maintainer decision template.
  • Add a current non-confidential decision for the alpha scope.
  • Define invalidation and re-review triggers.
  • Prohibit unsupported clearance, approval and non-infringement claims.
  • Remove external-audit requirements from the project plan.

Implementation

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions