Repository navigation
docs: contributor scaffolding — CONTRIBUTING, SECURITY, PR/issue templates, troubleshooting - #151
Merged
Merged
Conversation
…lates, troubleshooting (#144) CONTRIBUTING.md is the short human version of the constitution: fetch first, ADRs are constraints, task ci is done, three-pass workflow, test first, append-only ADRs with the template, commit types incl. ci, regenerate never hand-edit, found work becomes an issue, the label scheme. SECURITY.md routes reports through GitHub's private vulnerability reporting, scopes the template and the demo (ADR-031 abuse surface is deliberate; RLS bypass is the top class), and names the gates that run. The PR template asks for ADRs touched, the gate, the failing-test rule, regeneration, a CHANGELOG line, and new attack surface. Issue templates set the bug/enhancement/decision/docs type labels; config.yml points security reports away from public issues. docs/troubleshooting.md holds the recurring failures with cause and fix; docs/README.md and the README link the new files. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Contributor
Performance Budget Check ✅Binary Size: 14.91 MB / 20 MB |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #144. Stacked on the graduation PR; retarget to
masteronce that merges.CONTRIBUTING.md: the constitution in short — fetch first, ADRs are constraints,task ciis done, three-pass workflow, failing test first, append-only ADRs with the template, commit types includingci, regenerate never hand-edit, found work becomes an issue, the label scheme, agent scope.SECURITY.md: private reporting through GitHub's vulnerability reporting, what is in scope (template code, the demo per ADR-031's deliberate abuse surface, RLS bypass as the top class), the gates that run..github/PULL_REQUEST_TEMPLATE.md: ADRs touched, the gate, the failing-test rule, regeneration, CHANGELOG line, new attack surface..github/ISSUE_TEMPLATE/: bug / enhancement / decision / docs forms that set the type labels;config.ymlpoints security reports away from public issues.docs/troubleshooting.md: the recurring failures with cause and fix (DATABASE_URL encoding,authschema on vanilla Postgres, generator drift,versions:checkon Dependabot branches, the two hooks, the docker budget, 429s, theoplaunch config, the reset email template).docs/README.mdlink the new files.Needs your hands: enable Private vulnerability reporting under the repo's Settings → Code security, or
SECURITY.md's link lands on a page without the report button.Link check: 0 broken across 70 files.
🤖 Generated with Claude Code