Welcome! UbiCity follows the Tri-Perimeter Contribution Framework (TPCF).
Current Perimeter: 3 (Community Sandbox)
-
✅ Fully Open Contribution: Anyone can contribute via standard GitHub workflow
-
✅ No CLA Required: No contributor license agreements
-
✅ Democratic Review: Pull requests reviewed by maintainers and community
-
✅ Transparent Governance: Decisions documented in GitHub Issues/Discussions
| Perimeter | Name | Access | Use Case |
|---|---|---|---|
1 |
Core Maintainer |
Maintainers only |
Security-critical code |
2 |
Trusted Contributor |
Invited contributors |
Stable feature development |
3 |
Community Sandbox |
Public GitHub |
UbiCity (current) |
Why Perimeter 3? UbiCity is a community project. We welcome contributions from anyone who aligns with our values.
-
Fork the repository
-
Create a branch:
git checkout -b feature/your-feature -
Make changes (see below for guidelines)
-
Test:
just test(ortask test) -
Commit: Clear commit messages
-
Push:
git push origin feature/your-feature -
Pull Request: Open PR with description
-
Read the Code of Conduct
-
Check existing issues
-
Discuss major changes in an issue first
**Description**: Brief description
**Steps to Reproduce**:
1. Step one
2. Step two
**Expected**: What should happen
**Actual**: What actually happened
**Environment**:
- OS:
- version:
- UbiCity version:**Problem**: What problem does this solve?
**Solution**: Proposed solution
**Alternatives**: Other approaches considered
**Philosophy Alignment**: How does this align with UbiCity's values?-
**: For business logic (compile-time type safety)
-
Rust (WASM): For performance-critical code
-
**: For glue layer and I/O
# Format code
just fmt # or: fmt
# Lint code
just lint # or: lint
# Type check
just check # or: check src/**/*.ts# Run all tests
just test # or: task test
# Tests must pass
# Aim for >80% coverage for new code# Required
curl -fsSL https://deno.land/install.sh | sh # Deno
curl https://sh.rustup.rs -sSf | sh # Rust
npm install -g #
# Optional (but recommended)
cargo install just # just-
feat: New feature -
fix: Bug fix -
docs: Documentation only -
style: Code style (formatting, no logic change) -
refactor: Code refactoring -
perf: Performance improvement -
test: Adding tests -
chore: Build process, dependencies
feat(wasm): add Jaccard similarity calculation
Implement high-performance Jaccard similarity in Rust/WASM
for recommendation engine. 10x faster than JavaScript version.
Closes #42
---
fix(storage): handle ENOENT gracefully
loadAllExperiences() now returns empty array instead of throwing
when ubicity-data/ doesn't exist yet.
Fixes #56-
Philosophy Alignment: Does it fit UbiCity’s values?
-
Type Safety: Proper types in //Rust?
-
Tests: Adequate test coverage?
-
Documentation: Clear docs and comments?
-
Performance: No obvious performance issues?
-
Security: No vulnerabilities introduced?
-
First Response: Within 7 days
-
Merge Decision: Within 14 days (for simple PRs)
-
Complex PRs: May take longer, we’ll communicate
We use Semantic Versioning:
-
Major (v1.0.0): Breaking changes
-
Minor (v0.3.0): New features, backward compatible
-
Patch (v0.3.1): Bug fixes
Update CHANGELOG.md following Keep a
Changelog:
## [Unreleased]
### Added
- New feature X
### Changed
- Improved Y
### Fixed
- Bug Z (#issue)Contributors are recognized in: - git log (commit history) -
CHANGELOG.md (for significant contributions) -
.well-known/humans.txt - GitHub Contributors graph
-
GitHub Discussions: For questions and ideas
-
GitHub Issues: For bugs and feature requests
By contributing, you agree that your contributions will be licensed under:
Dual License: - MIT License (permissive) - Palimpsest v0.8 (values-aligned)
See LICENSE.txt for details.
Thank you for contributing to UbiCity! 🏙️
Remember: We’re building tools to capture informal learning, not platforms to control it. Every contribution should align with that philosophy.
Every commit that reaches the default branch must be signed; a ruleset refuses unsigned pushes. Estate policy: SIGNING-POLICY.
-
People and interactive agents sign with an SSH key registered on GitHub as a signing key (
gpg.format=ssh,user.signingkey=<key>.pub,commit.gpgsign=true). The committer email must be verified on that account. -
Apps, bots and workflows never
git pushlocal commits. They write through the API (createCommitOnBranchor the estatesigned-pushaction) so that GitHub signs each commit. -
Merge PRs with squash. The ruleset checks every commit on the PR branch, not just the result, so one unsigned commit blocks the merge. Re-create such a branch with signed commits (
git cherry-pick -S) and open a new PR. Rebase-merge replays commits unsigned and is disabled.