Skip to content

docs: contributor scaffolding — CONTRIBUTING, SECURITY, PR/issue templates, troubleshooting - #151

Merged
chrispezza merged 1 commit into
masterfrom
docs/contributor-scaffolding
Sep 30, 2026
Merged

chrispezza merged 1 commit into
masterfrom
docs/contributor-scaffolding

Conversation

@chrispezza

Copy link
Copy Markdown
Collaborator

Closes #144. Stacked on the graduation PR; retarget to master once that merges.

  • CONTRIBUTING.md: the constitution in short — fetch first, ADRs are constraints, task ci is done, three-pass workflow, failing test first, append-only ADRs with the template, commit types including ci, regenerate never hand-edit, found work becomes an issue, the label scheme, agent scope.
  • SECURITY.md: private reporting through GitHub's vulnerability reporting, what is in scope (template code, the demo per ADR-031's deliberate abuse surface, RLS bypass as the top class), the gates that run.
  • .github/PULL_REQUEST_TEMPLATE.md: ADRs touched, the gate, the failing-test rule, regeneration, CHANGELOG line, new attack surface.
  • .github/ISSUE_TEMPLATE/: bug / enhancement / decision / docs forms that set the type labels; config.yml points security reports away from public issues.
  • docs/troubleshooting.md: the recurring failures with cause and fix (DATABASE_URL encoding, auth schema on vanilla Postgres, generator drift, versions:check on Dependabot branches, the two hooks, the docker budget, 429s, the op launch config, the reset email template).
  • README and docs/README.md link the new files.

Needs your hands: enable Private vulnerability reporting under the repo's Settings → Code security, or SECURITY.md's link lands on a page without the report button.

Link check: 0 broken across 70 files.

🤖 Generated with Claude Code

…lates, troubleshooting (#144)

CONTRIBUTING.md is the short human version of the constitution: fetch
first, ADRs are constraints, task ci is done, three-pass workflow, test
first, append-only ADRs with the template, commit types incl. ci,
regenerate never hand-edit, found work becomes an issue, the label
scheme. SECURITY.md routes reports through GitHub's private vulnerability
reporting, scopes the template and the demo (ADR-031 abuse surface is
deliberate; RLS bypass is the top class), and names the gates that run.
The PR template asks for ADRs touched, the gate, the failing-test rule,
regeneration, a CHANGELOG line, and new attack surface. Issue templates
set the bug/enhancement/decision/docs type labels; config.yml points
security reports away from public issues. docs/troubleshooting.md holds
the recurring failures with cause and fix; docs/README.md and the README
link the new files.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@chrispezza
chrispezza changed the base branch from chore/graduate-checks to master September 30, 2026 21:20
@chrispezza chrispezza closed this Sep 30, 2026
@chrispezza chrispezza reopened this Sep 30, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Performance Budget Check ✅

Binary Size: 14.91 MB / 20 MB

@chrispezza
chrispezza merged commit 731e38f into master Sep 30, 2026
2 checks passed
@chrispezza
chrispezza deleted the docs/contributor-scaffolding branch September 30, 2026 21:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs: contributor scaffolding (CONTRIBUTING, SECURITY, PR/issue templates, docs/ index, troubleshooting)

1 participant