Open ASPM is currently maintained by the repository owner. Technical decisions are made in public issues, discussions, and pull requests whenever they do not involve embargoed security information.
Maintainers are responsible for project direction, releases, reviews, security response, and enforcement of the Code of Conduct. Contributors who establish a record of constructive, sustained participation may be invited to become maintainers. The maintainer model and decision process will evolve as the community grows.
Security-sensitive decisions may be discussed privately until coordinated disclosure is safe.