To be able to define how to install, run and maintain a core version of os2forms, documentation explaining the rationales behind the use of packagist packages needs to be documented.
A quick scan reveals these https://packagist.org/packages/os2forms/os2forms, but it is not explained in this documentation repo, where these packages are built, who maintains the build code, who owns the access to the package repo, how are they used, who maintains the source code for the packages or where security scans of the packages are performed.
To be able to define how to install, run and maintain a core version of os2forms, documentation explaining the rationales behind the use of packagist packages needs to be documented.
A quick scan reveals these https://packagist.org/packages/os2forms/os2forms, but it is not explained in this documentation repo, where these packages are built, who maintains the build code, who owns the access to the package repo, how are they used, who maintains the source code for the packages or where security scans of the packages are performed.