Skip to content

Latest commit

 

History

History
88 lines (59 loc) · 2.35 KB

File metadata and controls

88 lines (59 loc) · 2.35 KB

Contributing to Kaiten SDK for Python

Thank you for contributing to the Kaiten Python SDK.

This project is licensed under the Apache License, Version 2.0.

Developer Certificate of Origin

Kaiten uses the Developer Certificate of Origin 1.1 (DCO) for contributions.

Every commit must include a Signed-off-by trailer matching the commit author.

Use:

git commit -s -m "Describe your change"

This produces:

Signed-off-by: Jane Doe <jane@example.com>

git commit -s is a DCO sign-off: it certifies the contribution under DCO.md. git commit -S, with a capital S, is a cryptographic commit signature made with a GPG or SSH key. They are not the same thing, and the sign-off is what this project requires. There is nothing to install.

Fixing a missing sign-off

A check named DCO verifies every commit of every pull request, and it is the final word. If it fails, it names the commits to fix.

For the latest commit:

git commit --amend --signoff --no-edit
git push --force-with-lease

For several commits, sign off every commit of your branch at once:

git rebase --signoff origin/main
git push --force-with-lease

Contribution rules

Please:

  • keep pull requests focused;
  • add or update tests when behavior changes;
  • update documentation when relevant;
  • do not include secrets, customer data, or confidential information;
  • do not submit code or assets that you do not have the right to contribute;
  • preserve required third-party license and attribution notices.

Accepted contributions are contributed under Apache-2.0.

Before you open a pull request

The development workflows are Task targets over uv; the README's Development section lists them all.

task setup   # install the development environment
task check   # everything CI runs

Every Python file opens with the project's license notice:

# Copyright 2026 KAITEN INC
# SPDX-License-Identifier: Apache-2.0

The tests check it, generated files included. Never edit the generated src/kaitencloud/_sync/ or src/kaitencloud/types/ modules by hand: change the async source, the contract or a generator, then run task generate.

Security

Do not report unpatched vulnerabilities in public issues.

See SECURITY.md.