Description
We have various outstanding pull requests which have been approved by one or more of the TAP editors (#112, #122, #125, and #127).
From the TUF community meeting today, it appears that nobody knows quite what the expectations are for review and acceptance of specification changes.
Given the security sensitive nature of the project, it makes sense that pull requests would require a lengthy enough review period that the implications of a change can be reasoned about before the code is merged. However it is important for contributors to understand what the review process is and how proposed changes may eventually end up merged.
I propose we define a review standard review process which includes a number of reviewers and a contemplation period ensuring others have chance to comment. Then we should clearly document that process.