# Contributing ForgeFlow changes must preserve exact-commit provenance, update integrity and safe deployment boundaries. Before opening a pull request: - do not commit tokens, SSH credentials, signing private keys, deployment secrets or local repository state; - keep update manifests/checksums/signatures deterministic and reviewable; - add regression tests for repository synchronization, dirty-file handling, update and deployment changes; - keep real deployment targets configurable rather than embedding private infrastructure; - run `npm run quality` and the managed validation workflow where supported. Release metadata should distinguish an unreleased package version from the latest published Gitea Release; do not advance public release claims until the corresponding release exists.