AgentBOM is developed in the open under Apache-2.0. Changes to the normative specification and JSON Schema require pull request review and maintainer approval.
How decisions are made
1. **Issues** — bug reports, clarifications, and feature requests via GitHub Issues. 2. **RFCs** — substantive spec changes start as RFC documents in the repository. 3. **Maintainer review** — RFCs require approval from at least one maintainer before merge. 4. **Versioning** — breaking changes increment the major spec version; the schema URL is versioned accordingly.
Contributing
- Fork the repository and open a pull request.
- Sign commits per the Developer Certificate of Origin (DCO).
- Follow the project code of conduct on GitHub.
License
- **JSON Schema and @agentbom/verify:** Apache-2.0
- **Normative specification text:** CC-BY-4.0
Maintainers
We invite independent maintainers from the community. Founding maintainer disclosure appears below.