capa-rules/.github/CONTRIBUTING.md
Ana María Martínez Gómez 1aab323239
Add CONTRIBUTING file & update ISSUE TEMPLATES (#980)
* [ISSUE_TEMPLATE] Update Code of Conduct

Change Code of Conduct by Google's default Code of Conduct, as the used
linked has been removed from capa for consistency with other Google
projects.

* [CONTRIBUTING] Add CONTRIBUTING file

Add CONTRIBUTING file with information about CLA and Google's code of
conduct to follow Google conventions/policies. Include also other
details to make contributing easier.
2025-01-15 22:25:29 +01:00

2.3 KiB

Contributing capa rules

First off, thanks for taking the time to contribute! 💖

What should I know before I get started?

Code of Conduct

This project follows Google's Open Source Community Guidelines.

capa and its repositories

We host the capa project as three GitHub repositories:

  • capa-rules (this repository): The standard rules contributed by the community.
  • capa: The command line tools, logic engine, and other Python source code.
  • capa-testfiles: Test fixtures, such as malware samples.

Documentation

How Can I Contribute?

Issues

Open an issue to share a rules idea and report false positives/negatives. Check the open issues and ensure there is not already a similar issue.

Code (rule contributions)

Extend and enhance our rule set with a rule contributions based on your own ideas or the rule-idea issues.

Before contributing code

Before sending a pull request (PR):

  1. Sign the Contributor License Agreement
  2. Ensure each rule passes thorough linting (in rules directory: python ../scripts/lint.py --thorough -t "<your rule name>" -v .)
  3. [OPTIONAL, but greatly appreciated] Upload each referenced example binary to https://github.com/mandiant/capa-testfiles
  4. Please mention the issue your PR addresses (if any) in the PR description:
    closes https://github.com/mandiant/capa-rules/issues/<issue_number>
    
Contributor License Agreement

Contributions to this project must be accompanied by a Contributor License Agreement (CLA). You (or your employer) retain the copyright to your contribution; this simply gives us permission to use and redistribute your contributions as part of the project.

If you or your current employer have already signed the Google CLA (even if it was for a different project), you probably don't need to do it again.

Visit https://cla.developers.google.com/ to see your current agreements or to sign a new one.