Currently anyone who ever was a maintainer in any evaluated commit will be considered a maintainer:
https://github.com/Nix-Security-WG/nix-security-tracker/blob/1ad5409158e789b9de9d682687a09ccda2394a45/src/shared/auth/utils.py#L17-L20
Change it such that only people who are maintainers at the tip of any of the tracked branches have maintainer permissions.