gittuf/CONTRIBUTING.md
Aditya Sirish A Yelgundhalli 9a54f11a70
docs: Mention GAPs in CONTRIBUTING.md
Signed-off-by: Aditya Sirish A Yelgundhalli <ayelgundhall@bloomberg.net>
2025-01-20 12:36:19 -05:00

1.9 KiB

Contributing Guide

Contributions to gittuf can be of several types:

Join our community to get started!

Contributor Workflow

When submitting changes to the gittuf docs or implementation, contributors must open a GitHub pull request to the repository. If a proposed change is a significant deviation from gittuf's design document, a GAP may be necessary. When in doubt, contributors are advised to file an issue in the repository for the maintainers to determine the best way forward.

gittuf uses the NYU Secure Systems Lab development workflow. Pull requests must include tests for the changes in behavior they introduce. They are reviewed by one or more maintainers and undergo automated testing such as (but not limited to):

  • Unit and build testing
  • Static analysis using linters
  • Developer Certificate of Origin (DCO) check

In future, as gittuf matures, this repository will also be secured using gittuf. At that point, the contributor workflow may evolve to record gittuf specific information.

Other Guidelines

Contributors to gittuf must abide by the project's code of conduct. Any questions regarding the gittuf community's governance and code of conduct may be directed to the project's Technical Steering Committee.