Thank you for your interest in contributing.
-
Fork the repository
-
Create a feature branch (
feat/my-feature) -
Ensure SPDX headers on all new files (
MPL-2.0) -
Run
panic-attack assailbefore committing -
Submit a pull request
-
All code must have detailed annotations
-
No dangerous patterns:
believe_me,assert_total,sorry,Admitted,unsafeCoerce,Obj.magic -
Tests required for new functionality
Jonathan D.A. Jewell j.d.a.jewell@open.ac.uk
Every commit that reaches the default branch must be signed; a ruleset refuses unsigned pushes. Estate policy: SIGNING-POLICY.
-
People and interactive agents sign with an SSH key registered on GitHub as a signing key (
gpg.format=ssh,user.signingkey=<key>.pub,commit.gpgsign=true). The committer email must be verified on that account. -
Apps, bots and workflows never
git pushlocal commits. They write through the API (createCommitOnBranchor the estatesigned-pushaction) so that GitHub signs each commit. -
Merge PRs with squash. The ruleset checks every commit on the PR branch, not just the result, so one unsigned commit blocks the merge. Re-create such a branch with signed commits (
git cherry-pick -S) and open a new PR. Rebase-merge replays commits unsigned and is disabled.