Contributions to 0patch-lsa-sentinel follow the Hyperpolymath estate conventions:
AsciiDoc for documentation, Conventional Commits, and real (not mocked)
integration tests where the estate policy applies.
This repository ships a Justfile; just lists the available recipes.
git clone git@github.com:hyperpolymath/0patch-lsa-sentinel.git
cd 0patch-lsa-sentinel
just # lists the available recipes-
Search existing issues first; check whether
mainalready fixes the problem. -
Use the issue templates where present; include environment details, steps to reproduce, and expected vs actual behaviour.
docs/short-description # Documentation
test/what-added # Test additions
feat/short-description # New features
fix/issue-number-description # Bug fixes
refactor/what-changed # Code improvements
security/what-fixed # Security fixesWe follow Conventional Commits:
<type>(<scope>): <description>
[optional body]
[optional footer]This root document exists because the estate docs gate
(hyperpolymath/standards scripts/check-docs-presence.sh) requires
CONTRIBUTING.md, CONTRIBUTING.adoc, or 3-practice/CONTRIBUTING.adoc
at the repository root. Estate documentation policy: AsciiDoc by default —
see hyperpolymath/standards.
Every commit that reaches the default branch must be signed; a ruleset refuses unsigned pushes. Estate policy: SIGNING-POLICY.
-
People and interactive agents sign with an SSH key registered on GitHub as a signing key (
gpg.format=ssh,user.signingkey=<key>.pub,commit.gpgsign=true). The committer email must be verified on that account. -
Apps, bots and workflows never
git pushlocal commits. They write through the API (createCommitOnBranchor the estatesigned-pushaction) so that GitHub signs each commit. -
Merge PRs with squash. The ruleset checks every commit on the PR branch, not just the result, so one unsigned commit blocks the merge. Re-create such a branch with signed commits (
git cherry-pick -S) and open a new PR. Rebase-merge replays commits unsigned and is disabled.