Skip to content

access continuity

github-actions[bot] edited this page Oct 3, 2026 · 1 revision

Access continuity

Status: shipped. One gap is open.

This page says what happens if the maintainer cannot act. Today there is one maintainer. We say so plainly.

What exists today

  • Successor setting. GitHub lets a personal account name a successor. A successor can take over the repositories of the account if the owner can no longer act. See GitHub: Maintaining ownership continuity of your personal account's repositories. The maintainer will name a successor. No successor is named yet.
  • Recovery material. The account recovery codes and the release signing setup are kept in a password manager. The password manager has an emergency-access contact.
  • No private release key. Releases carry no private key that one person holds. The release workflow signs each release file with cosign, keyless, through Sigstore and the GitHub Actions OIDC identity. It also attests build provenance. The maintainer signs release tags with a personal SSH key, but that is a practice and not a gate: the release does not check the tag signature. A successor with admin rights on the repository can release with no key handover. See Release pipeline. The attestation step runs only while the repository is public.
  • Everything is in the repository. The code, the docs, the CI and the release steps are in git. A new maintainer can rebuild all of it.

What is still needed

  • A second person with admin rights on the repository.
  • A named successor in the GitHub successor settings.
  • A second active maintainer who can review and release.

Open gap

This is open. There is no second active maintainer. If the maintainer is unavailable, nobody else can merge, release or answer a security report until the successor process finishes. These OpenSSF Gold criteria stay unmet until a second maintainer joins: bus_factor, contributors_unassociated and two_person_review.

The project wants a co-maintainer. See the roadmap and Governance.

History

  • 2026-10-03 — Add the governance pages — #30.

Clone this wiki locally