diff --git a/.github/ISSUE_TEMPLATE/bug.yml b/.github/ISSUE_TEMPLATE/bug.yml new file mode 100644 index 0000000..4d8661e --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug.yml @@ -0,0 +1,64 @@ +name: Bug report +description: Something returned the wrong answer, failed, or contradicted its own receipt. +labels: ["bug"] + +body: + - type: markdown + attributes: + value: >- + **Stop if this involves provenance or personal data.** A forged or + missing citation, a wrong `retrieved_at`, or anything exposing an + individual person is a security issue — report it privately through + [security advisories](https://github.com/citature/.github/security/advisories/new) + rather than here. Everything else belongs in this form. + + - type: input + id: surface + attributes: + label: Tool or actor + description: The MCP tool name or the Apify actor, as you called it. + placeholder: follow_the_money · govcon-recompetes + validations: + required: true + + - type: textarea + id: input + attributes: + label: What you ran + description: The exact arguments or actor input. Redact nothing — these are public records. + render: json + validations: + required: true + + - type: textarea + id: expected + attributes: + label: What you expected, and what you got instead + validations: + required: true + + - type: textarea + id: receipt + attributes: + label: The receipt + description: >- + Paste the receipt envelope from the answer if you have it — the citation, + `retrieved_at`, and match provenance. It is usually the fastest route to + the cause, because it says which upstream file the answer came from. + render: json + validations: + required: false + + - type: dropdown + id: source + attributes: + label: Which source does this touch? + multiple: true + options: + - FEC + - USASpending + - SAM.gov + - Grants.gov + - Not sure + validations: + required: false diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml new file mode 100644 index 0000000..cdd0677 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -0,0 +1,16 @@ +blank_issues_enabled: false + +contact_links: + - name: Vulnerability, provenance, or personal-data concern — report privately + url: https://github.com/citature/.github/security/advisories/new + about: >- + Do not open a public issue. Anything that could let a citation, retrieval + timestamp, or source locator be forged, and anything involving personal + data, goes here privately. See SECURITY.md for scope. + + - name: Incorrect data in a federal source + url: https://github.com/citature/.github/issues/new?template=bug.yml + about: >- + If a government source itself published something wrong, that is an + upstream data issue rather than a citature bug. File it as a bug report + and it will be documented as a coverage caveat.