Community Governance

August 15, 2026 · View on GitHub

Chinese | English

oh-my-dsh is a shared collaboration layer, not the governing committee of a plugin marketplace. It coordinates common boundaries, contribution paths, upstream compatibility, public decisions, safety, and conduct while preserving project autonomy and a plural ecosystem.

This proposal applies to an asset only after that asset's controller confirms the scope in writing. Only a rule confirmed by both omdsh-dev and oh-my-dsh may be described as cross-organization governance.

Principles

  1. Project autonomy and repository-scoped authority.
  2. Multiple catalogs, markets, distributions, and allowlists may coexist.
  3. Public participation does not require organization membership.
  4. Routine reversible work uses the lightest accountable process.
  5. Root access, security, conduct, sanctions, funds, brand, and irreversible actions require explicit authority and review.
  6. Decisions state scope, reasons, owner, review/expiry date, and rollback.
  7. Confidential cases are minimized; public records use de-identified metadata.

Trial responsibilities

  • Facilitator: agenda and meeting scope.
  • Recorder: proposals, decisions, objections, owners, and review dates.
  • Community Maintainer: this repository and participation routes.
  • Compatibility Coordinator: upstream breaking changes and affected projects.
  • Security/Conduct Contact: sensitive intake and non-conflicted review.

These are temporary responsibilities, not permanent ranks. The proposer, decision-maker, and appeal reviewer must not be the same person in a sensitive case. If no independent reviewer is available, pause or seek a temporary external reviewer.

Decisions

ClassExamplesTrial processTimeout default
RoutineDocs, metadata, reversible maintenanceProject maintainer review; automation where suitableMay proceed with rollback recorded
ProjectFeatures and ordinary project policyMaintainers decide in their repositoryCurrent state if no owner
Cross-projectShared schema, compatibility conventionPublic proposal; normally 72 hours for objectionsRemains a proposal/current state
High-impactRoot assets, org rules, brand, funds, sanctions, CoC, irreversible removalConfirmed controller; recusal, response, reasons, independent reviewNever passes by silence
EmergencyActive serious harmLeast intrusive temporary actionReview in 72 hours or expire

The 72-hour window is a trial parameter. It starts after a complete proposal reaches the agreed channel and pauses on a substantive objection.

Meetings and records

A meeting is non-binding unless the applicable controller delegated authority in advance; otherwise the output is a proposal awaiting asynchronous ratification. Public records include identifier, date, scope, alternatives, evidence, reasons, decision-maker, recusals, owner, deadline, rollback, review date, and status.

Vulnerabilities, conduct reports, personal data, secrets, and recovery details must not enter public proposals or minutes.

Contribution and access

The lightweight path is Participant → Contributor → Triager → Repository Maintainer/Steward → Emeritus. Access is repository-scoped and based on demonstrated work. During the trial, one non-conflicted sponsor plus public contribution evidence and a 90-day review is sufficient. Offboarding removes unneeded team, publisher, token, and recovery access.

Review and expiry

On day 30, review contributor response, upstream compatibility response, governance-blocked work, volunteer burden, bypass behavior, safety, and due process. Continue, simplify, pause, or expire. Without explicit renewal by applicable controllers, the trial expires. A discovery-only ecosystem is an acceptable outcome.