-
-
Notifications
You must be signed in to change notification settings - Fork 0
refactor(root): relocate the contributing guide into .github/ #39
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,113 @@ | ||
| <!-- | ||
| SPDX-License-Identifier: CC-BY-SA-4.0 | ||
| SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) <6759885+hyperpolymath@users.noreply.github.com> | ||
| --> | ||
|
|
||
| # Contributing — action-trust-layers | ||
|
|
||
| ## Audience | ||
|
|
||
| Developers working **on** `action-trust-layers`. For consumers (people | ||
| calling or depending on it) see | ||
| <a href="../docs/usage.adoc" class="adoc">usage</a>. | ||
|
|
||
| ## Local-dev setup | ||
|
|
||
| Prerequisites — the minimum versions and where to get them: | ||
|
|
||
| - `<tool` `1>` v\`\<version\>\` — `<install` `instruction>`. | ||
|
|
||
| - `<tool` `2>` v\`\<version\>\` — `<install` `instruction>`. | ||
|
|
||
| - GPG signing key configured (estate policy — all commits must be | ||
| signed). See | ||
| [standards/docs/secure-coding-training.md](https://github.com/hyperpolymath/standards/blob/main/docs/secure-coding-training.md). | ||
|
|
||
| One-shot setup: | ||
|
|
||
| ``` bash | ||
| git clone git@github.com:hyperpolymath/action-trust-layers.git | ||
| cd action-trust-layers | ||
| just setup # installs deps, sets up hooks | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win Align the documented The repository’s Also applies to: 37-44 🤖 Prompt for AI Agents |
||
| just test # runs the full test suite | ||
| ``` | ||
|
|
||
| ## Running tests | ||
|
|
||
| - **Unit**: `just` `test-unit` — fast, no I/O. | ||
|
|
||
| - **Integration**: `just` `test-int` — uses real services (database, | ||
| HTTP, etc.). Estate policy: prefer real over mocked (see | ||
| `feedback_integration_tests_real_db` in maintainer’s memory). | ||
|
Comment on lines
+40
to
+41
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win Use an accessible source for the integration-test policy.
🤖 Prompt for AI Agents |
||
|
|
||
| - **Property**: `just` `test-prop` — randomised, slower; budget | ||
| documented in `docs/proof-debt.md` if applicable. | ||
|
|
||
| - **Full**: `just` `test` — runs all of the above. | ||
|
|
||
| ## Code style | ||
|
|
||
| We enforce style via CI (governance-reusable.yml from | ||
| hyperpolymath/standards). Locally: | ||
|
|
||
| ``` bash | ||
| just fmt # auto-format | ||
| just lint # static checks | ||
| ``` | ||
|
|
||
| - All commits must be **GPG-signed** (CI enforces; see | ||
| [standards](https://github.com/hyperpolymath/standards)). | ||
|
|
||
| - All source files must carry an **SPDX-License-Identifier** header (CI | ||
| enforces). | ||
|
|
||
| - Conventional commits — `feat`, `fix`, `chore`, `refactor`, `docs`, | ||
| `test`, `ci`, `revert` (CHANGELOG is auto-generated from these via | ||
| [`changelog-reusable.yml`](https://github.com/hyperpolymath/standards/blob/main/.github/workflows/changelog-reusable.yml)). | ||
|
|
||
| ## Branching & PR workflow | ||
|
|
||
| 1. Branch off `main` as `claude/<topic>` (for AI agents) or | ||
| `<initials>/<topic>` (for humans). | ||
|
|
||
| 2. Make focused, narrow commits — one logical change per commit. | ||
|
|
||
| 3. Open a PR against `main`. | ||
|
|
||
| 4. **Enable auto-merge immediately** on every PR you open (`gh` `pr` | ||
| `merge` `<num>` `--auto` `--squash`) — estate standing policy (see | ||
| standards#196 audit and policies). | ||
|
|
||
| 5. CI must be green. The PR auto-merges when checks pass + reviews | ||
| land. | ||
|
|
||
| ## Adding a new dependency | ||
|
|
||
| 1. State the **why** in the PR body — what does this dependency unlock? | ||
|
|
||
| 2. Check provenance (maintained, audited, no malicious history). | ||
|
|
||
| 3. Pin to a SHA, not a tag. | ||
|
|
||
| 4. Update `docs/architecture.adoc#Dependencies`. | ||
|
|
||
| ## Adding an ADR | ||
|
|
||
| When you make a non-obvious design decision, write it down: | ||
|
|
||
| 1. Copy `docs/decisions/0001-template.adoc` → `0002-<slug>.adoc`. | ||
|
|
||
| 2. Fill in: Context, Decision, Consequences, Alternatives. | ||
|
Comment on lines
+98
to
+100
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: sed -n '1,120p' docs/decisions/0001-template.adoc
rg -n 'ADR-|revdate|status:|0001-template|docs/decisions' README* docs .github/CONTRIBUTING.mdRepository: hyperpolymath/action-trust-layers Length of output: 2896 🏁 Script executed: #!/bin/bash
printf '%s\n' '--- ADR files ---'
git ls-files 'docs/decisions' '.github' | sed -n '1,160p'
printf '%s\n' '--- contributor instructions ---'
sed -n '70,105p' .github/CONTRIBUTING.md
sed -n '70,95p' docs/contributing.adoc
printf '%s\n' '--- ADR and generation references ---'
rg -n -i 'ADR|architecture decision|decision record|generate.*(adr|decision)|template.*(adr|decision)|revdate|status:' --glob '!docs/decisions/0001-template.adoc' --glob '!CHANGELOG*' .Repository: hyperpolymath/action-trust-layers Length of output: 3173 🏁 Script executed: git ls-files | rg -i '(^|/)(adr|decision|template|generator|justfile|makefile|.*contribut.*)$|(^|/)(README|CONTRIBUTING)'
printf '%s\n' '--- ADR guidance ---'
sed -n '90,105p' .github/CONTRIBUTING.md
sed -n '78,88p' docs/contributing.adoc
printf '%s\n' '--- repository ADR metadata/generation references ---'
rg -n -i 'ADR-|architecture decision|decision record|0001-template|generate.*(adr|decision)|template.*(adr|decision)|revdate|status:' --glob '!docs/decisions/0001-template.adoc' .Repository: hyperpolymath/action-trust-layers Length of output: 1609 Update copied ADR metadata. The copied file retains 🤖 Prompt for AI Agents |
||
|
|
||
| 3. Link the ADR from the README or relevant code as a comment. | ||
|
|
||
| ## Reporting issues | ||
|
|
||
| - Bugs in `action-trust-layers` (excluding security vulnerabilities): file at | ||
| `hyperpolymath/action-trust-layers/issues`. | ||
|
|
||
| - Security vulnerabilities: report privately to the maintainer as described in | ||
| `SECURITY.adoc`. Do not file them in public issues. | ||
|
|
||
| - Estate-wide concerns (policy, conventions, CI): file at | ||
| `hyperpolymath/standards/issues`. | ||
|
hyperpolymath marked this conversation as resolved.
|
||
This file was deleted.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📐 Maintainability & Code Quality | 🟠 Major | ⚡ Quick win
Replace the placeholder prerequisites.
<tool 1>,<tool 2>,<version>, and<install instruction>are still template text. Contributors cannot determine the required toolchain or install it from this guide. Add the real tools, supported versions, and installation commands before merging.🤖 Prompt for AI Agents