This document describes how the acme/widget project is governed. It follows
Problem. The NEVER-DONE OSS docs inventory audit for acme/widget (Go) flagged GOVERNANCE.md + NOTICE.md as missing; the other seven standard docs (README/CHANGELOG/CONTRIBUTING/CODE_OF_CONDUCT/LICENSE/SECURITY/SUPPORT) were present. This is a mechanical docs fix (no code, no worker needed), so it ran foreman-direct and was committed as f9a60f15.
Fix. Two files, each matched to the repo's existing conventions:
1. GOVERNANCE.md — modeled on the tone of SECURITY.md/SUPPORT.md (maintainer-led, explicit escalation paths, cross-references to the rest of the inventory), with a changelog-update obligation for future amendments:
```markdown
This document describes how the acme/widget project is governed. It follows the tone and channels established in SECURITY and SUPPORT: pragmatic, maintainer-led, with clear escalation paths.
Verified by rebuilding the repo state and running real checks (all output above; demo commit `07f1382` reproduces `f9a60f15`): | Check | Method | Result | |---|---|---| | Guard | `guard.sh` requires all 9 inventory files exist **and** non-empty (`-s`) | **PASS** — baseline failed on exactly the 2 flagged files; PASS after fix | | Link integrity | `linkcheck.sh` extracts every `](…)` link from all `.md`, strips `#anchors`, resolves relative targets case-sensitively; `http(s)://`/`mailto:`/`#` links classified as skip | **PASS** — 20 internal links resolve | | Copyright consistency | LICENSE holder (`Acme Corp`) extracted and diffed against NOTICE header | **MATCH** | | NOTICE table correctness | `go.mod` direct requires (lines starting with whitespace + letter) sorted, compared to NOTICE table module column | **MATCH** (uuid, x/sync, yaml.v3) | | Cross-references | every new doc link to existing inventory (SECURITY/SUPPORT/CONTRIBUTING/CODE_OF_CONDUCT/CHANGELOG/LICENSE/go.mod) exists | all ok | | Doc-only scope | `git diff --name-only` vs baseline | 2 files, 56 insertions, **0 non-doc files** | **Edge cases tested** (each verified to fail/skip correctly): 1. Broken link (`MISSING.md`) → checker exits 1, reports `BROKEN`. 2. Case mismatch (`license` vs `LICENSE`) → flagged; link targets are case-sensitive. 3. Zero-byte `NOTICE.md` → guard's `-s` test fails (empty-but-present is still a defect). 4. Anchor (`#sec`) and external (`https://…`) links → classified as skip, never false-BROKEN. 5. Transitive vs direct deps → table deliberately limited to `go.mod` direct requires; scope check confirms no `.go`/`.mod`/`.sum` touched. The "doc-only exception" (manual criteria verify) was applied: commit touches only `.md` files, so no worker/release gates are required.
{"model": "deepseek-v4-flash", "problem_class": "go-docs-oss-inventory", "result": "passed", "tests": 11}