Skip to content

Finalize governance, security contact and brand control setup #12

Description

@mastertape

The first governance and commercial-positioning documents exist, but a few project-critical decisions still need explicit setup before the project grows.

Acceptance criteria:

  • GitHub private vulnerability reporting is enabled for public repositories.
  • Public security contact wording is finalized; security@openparcelbox.org is only used once the mailbox exists and is monitored.
  • License split is reviewed again once real firmware, server, hardware and documentation directories exist.
  • Trademark/brand policy wording is reviewed before any certification or commercial product claim is made.
  • Contribution path is completed with DCO check automation and branch protection once pull requests start.
  • Future legal structure options are documented: foundation, cooperative, association, company or similar.
  • Brand ownership/control is explicitly kept separate from any later operating structure unless changed by written agreement.

Private reference:

  • OpenParcelBox/openparcelbox-research-inbox: results/reviewed/2026-05-13-governance-critical-notes.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:documentationDocumentation and websitearea:projectProject foundation and governancearea:securitySecurity, safety and abuse preventionpriority:P1Important for first prototype

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions