Skip to content

Add accurate contributor guidance and validated community/review metadata #127

Description

@jmanico

Reviewed 2026-09-25 (America/Los_Angeles) against main at bd249f5. Execution order and cross-issue ownership: #169. Batch 05.

This scope replaces the dated implementation prescriptions in the original report and earlier comments; linked historical evidence remains useful but must be rechecked before implementation.

  • Add project-specific CONTRIBUTING.md with current build/runtime requirements, verify/optional browser/ESAPI commands, compatibility/parity checks, actual style/coverage status and output-change documentation expectations. Reuse Add isolated packaged-consumer compatibility CI across Java 8–25 #162/Document independent signing-key custody and recovery #164 guidance rather than inventing a new maintainer process.
  • Describe current review rules and a realistic triage policy. DCO, response-time promises and mandatory owner review are explicit maintainer policy decisions, not defaults introduced by a documentation PR.
  • Link the current OWASP Code of Conduct and route suspected vulnerabilities privately through SECURITY.md; public bug forms must not encourage posting vulnerability proofs.
  • Add concise issue/PR forms for reproducible ordinary bugs, context questions and scoped features. Do not route users to Discussions until it exists; decide on Discussions/blank-issue policy explicitly.
  • Validate any CODEOWNERS user/team exists and has the required repository access. Do not assume @OWASP/owasp-java-encoder is valid without checking. Harden repository settings in stages after verifying CI and release-tag protections #108 owns whether owner approval becomes a branch rule.
  • Add accurate funding links consistent with the funding manifest merged in Add .well-known/funding-manifest-urls for FLOSS/fund #157. Verify links and GitHub community metadata after changes.
  • Keep non-goals current: JSON and ordinary untagged-template support now exist, so old closed requests are historical context, not evidence that those features are still rejected.

Coordinate final commands with #122, style with #124, release notes with #115 and README navigation with #128. Do not reopen declined feature/tooling proposals as incidental community-file work.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: docsConsumer/contributor documentation and project metadata.documentationenhancementpriority: P2Planned maintenance; follow the ordered batch and documented dependencies.triage: readyScope reviewed; actionable within its batch, subject to the normal PR process.

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions