The project is maintainer-led. Maintainers set release policy, approve public profile labels, manage security response, and merge pull requests after required checks.
Normal changes require one maintainer approval and passing required checks. Changes to licensing, exporter policy, security controls, workflows, trusted measurements, or verified-profile rules require two maintainer approvals. Maintainers may use a temporary hold when a release, privacy, safety, or legal concern is unresolved.
Public releases are created only through the documented export workflow. The public repository has no automatic mirror of private development.