This commit is contained in:
@@ -0,0 +1,22 @@
|
||||
# Contributing
|
||||
|
||||
Contributions must preserve Pulse's read-only observability and evidence boundaries.
|
||||
|
||||
Start with a focused issue or proposal for material behavior changes. Keep pull requests small enough to review, explain the user-visible outcome, and include tests for the changed boundary.
|
||||
|
||||
- use synthetic telemetry and isolated test databases;
|
||||
- never commit production dashboards, host inventories, credentials, backups or alert payloads;
|
||||
- keep application changes separate from agent/planning/evidence updates;
|
||||
- document new data collection, retention, authorization and network behaviour;
|
||||
- run the repository's managed validation and the relevant Go, frontend, integration and Compose checks;
|
||||
- retain provenance for screenshots and evidence summaries, and keep generated heavy artifacts outside Git.
|
||||
|
||||
Changes that alter the read-only promise, OIDC/RBAC policy, backup format, agent privileges or deployment topology require explicit security review. Report sensitive findings through `SECURITY.md`.
|
||||
|
||||
For a public source checkout, run:
|
||||
|
||||
```powershell
|
||||
pwsh -NoProfile -File scripts/public-verify.ps1
|
||||
```
|
||||
|
||||
Go code must be formatted with `gofmt`; frontend changes must pass tests, typecheck, lint, and build. Do not weaken a failing gate or replace a real integration boundary with a mock merely to obtain a green result.
|
||||
Reference in New Issue
Block a user