-
Notifications
You must be signed in to change notification settings - Fork 8
Define policy pack contribution and quality standards #21
Copy link
Copy link
Open
Labels
area: standardsFramework packs, OSCAL, and conformanceFramework packs, OSCAL, and conformancecommunity-readyScoped contribution ready for community collaborationScoped contribution ready for community collaborationdocumentationImprovements or additions to documentationImprovements or additions to documentationenhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededpriority: p1Important follow-up after P0 foundationsImportant follow-up after P0 foundations
Description
Activity
Metadata
Metadata
Assignees
Labels
area: standardsFramework packs, OSCAL, and conformanceFramework packs, OSCAL, and conformancecommunity-readyScoped contribution ready for community collaborationScoped contribution ready for community collaborationdocumentationImprovements or additions to documentationImprovements or additions to documentationenhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededpriority: p1Important follow-up after P0 foundationsImportant follow-up after P0 foundations
Why this matters
Policy packs are where DocSentinel turns generic security review into actionable governance. They also carry a high risk of becoming opaque, stale, or biased if contribution rules are not explicit.
From first principles: a policy rule is only useful if contributors can inspect its source, version, rationale, applicability, and test coverage.
Community help wanted
We need a contribution model and quality bar for public policy packs.
Suggested scope
Acceptance criteria