nostrbasedocs
Start building
Guide
.md

The project owner is accountable for this repository. No GitHub account, npm organization, or security contact has been assigned. Assign named people before hosting or publication; then add CODEOWNERS with those real accounts. This role map is local policy, not enforced GitHub approval.

Area Responsible role Review focus
src/, protocol, public declarations SDK maintainer API compatibility, signed data, ownership, encryption, partial receipts
src/group*.ts, vendor/, private group protocol SDK maintainer and reviewer familiar with MLS Membership, convergence, encrypted device state, exact replay, engine provenance and patches
tests/, integration/, test setup SDK maintainer Independent evidence, deterministic faults, cleanup, pinned software
site/, docs/, examples Documentation maintainer Working examples, links, accessibility, accurate feature claims
.github/, .githooks/, scripts/, lockfiles Repository maintainer Least privilege, reproducibility, supply chain, local/CI parity
Security reports and release approval Project owner Private handling, risk decisions, publication authority

One person can fill several roles. A substantive change needs an independent reviewer before merge. Authentication, author checks, private data, protocol changes, and releases need review by someone who can assess that risk. Routine documentation changes need one relevant reviewer; no fixed reviewer count or coverage target applies.

Record the scope, acceptance criteria, risk, checks run, and remaining limits in the pull request or local review record. CI does not replace review. Review requirements remain unenforced until the hosted repository has branch rules.

Search guides, API methods, and protocols.