- Open or reference an issue describing the behavior change.
- Create a feature branch; do not push directly to
main. - Update
.trust.toml, specs, tests, and documentation when their contracts change. - Run
fledge lanes run verifylocally. - Open a pull request using the repository template and wait for required checks and approval.
Trust orchestration must never silently weaken a committed gate. Security reports belong in private vulnerability reporting, not public issues.