From f0de61ea561a0857282370528bf7bd16989a9c6b Mon Sep 17 00:00:00 2001 From: Ayla Croft Date: Wed, 23 Sep 2026 15:54:59 -0400 Subject: [PATCH] Continuity: Mike Hostetler now holds Maintain as well as Hex maintainer; secure 2FA required Measured 2026-09-23: GitHub lists mikehostetler as a collaborator with role maintain on beam_mcp and beam_mcp_signer (invitation accepted), beside his maintainer ownership of both packages on hex.pm, so he alone can carry every step from issue to published release. The ScriptKittyOS organization requires two-factor authentication (two_factor_requirement_enabled true), secure methods only. The pages said he was invited; they now say he holds it. Copy only. Signed-off-by: Ayla Croft --- CHANGELOG.md | 2 ++ GOVERNANCE.md | 2 +- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9d29661..c9d3e0d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -19,6 +19,8 @@ SPDX-License-Identifier: Apache-2.0 - `GOVERNANCE.md` names two continuity holders, as on `beam_mcp`: `znmead` (the Maintain role on this repository) and Mike Hostetler (`maintainer` ownership on hex.pm; invited to Maintain), what that covers and what it does not. The bus factor stays one for knowledge. + Mike Hostetler has since accepted Maintain here too; the organization requires secure + two-factor authentication. ### Added diff --git a/GOVERNANCE.md b/GOVERNANCE.md index aedd5f5..a1d9e77 100644 --- a/GOVERNANCE.md +++ b/GOVERNANCE.md @@ -16,7 +16,7 @@ apply here, and this page says what is particular to this repository. | role | who | responsibilities | |---|---|---| | **Maintainer** | one person: the ScriptKittyOS organization's administrator, the `full` hex.pm owner of `beam_mcp_signer` (account `aylacroft`), and the address in `SECURITY.md` | decides what lands and when; reviews every pull request; keeps CI green; answers security reports on `SECURITY.md`'s commitments; tags (signed) and publishes releases; keeps this page, the roadmap and the CHANGELOG true | -| **Continuity holders** | two people, from 2026-09-23, the same as on `beam_mcp`: `znmead`, the Maintain role on this repository; Mike Hostetler (`mikehostetler`), `maintainer` ownership of `beam_mcp_signer` on hex.pm, invited to Maintain here too | if the maintainer cannot act, keep the project going within a week between them: triage and close issues, merge pull requests once CI is green, tag (signed with their own key, announced in the CHANGELOG with its fingerprint) and publish releases; decide nothing while the maintainer can | +| **Continuity holders** | two people, from 2026-09-23, the same as on `beam_mcp`: `znmead`, the Maintain role on this repository (re-invited on 2026-09-23 when the organization began requiring secure two-factor methods; pending his acceptance); Mike Hostetler (`mikehostetler`), the Maintain role here and `maintainer` ownership of `beam_mcp_signer` on hex.pm, so he alone covers every step from issue to published release; the organization requires secure two-factor authentication | if the maintainer cannot act, keep the project going within a week between them: triage and close issues, merge pull requests once CI is green, tag (signed with their own key, announced in the CHANGELOG with its fingerprint) and publish releases; decide nothing while the maintainer can | | **Contributor** | anyone | proposes changes by pull request under `CONTRIBUTING.md`: signed off, tested, green; reports bugs and enhancements as issues; reports vulnerabilities privately | There is no steering group and no vote. A decision is the maintainer's and is recorded in the