Skip to content
VERASPEC
Repository
Governancestable

§5 How an objection is heard

Where to raise one: a public GitHub issue labeled objection. If the objection concerns a security-relevant defect, or is otherwise sensitive, use the private route in `SECURITY.md` instead — the same substance, a different venue, chosen for the same reason SECURITY.md gives: some things should not be public before there is a disposition.

The commitment: every objection gets a written dispositionaccepted, accepted-with-changes, or rejected-with-reasons — recorded in the ADR the objection concerns, or in the review report (§6) if it was raised during a review period. rejected-with-reasons means the reasons are written down, not just the outcome.

No time-based auto-dismissal. An objection stays open until it has a disposition; it is never closed because a clock ran out. This is distinct from SECURITY.md's 30-day acknowledgment window for vulnerability reports, which is an escalation path for silence (open a non-specific public issue asking the maintainer to check the queue), not a dismissal — the underlying report stays open either way.