Skip to content

docs: the community health files a stranger looks for before adopting this - #49

Merged
blairham merged 1 commit into
mainfrom
launch-43
Sep 8, 2026
Merged

blairham merged 1 commit into
mainfrom
launch-43

Conversation

@blairham

@blairham blairham commented Sep 8, 2026

Copy link
Copy Markdown
Owner

Part of the launch-readiness work in #43. Attribution, the name collision and the shared-cache warning already landed; the community health files did not, and their absence is what a prospective adopter notices first.

What this adds

File Why it is shaped this way
CONTRIBUTING.md Leads with the divergence report as the most valuable contribution, because it is the one class of bug this project cannot find for itself. States plainly that divergence is a bug and never a feature, and that a capability upstream lacks belongs on upstream's tracker.
SECURITY.md Draws the boundary where it actually falls for a hook runner: the tool downloads and executes code by design, so the question is whose code and whether it can be made to run something unasked. Checksum verification in the action, path handling in the store, config parsing are in scope; a hostile entry in your own config is not.
CODE_OF_CONDUCT.md Contributor Covenant 2.1, unmodified apart from the contact address.
.github/ISSUE_TEMPLATE/ divergence.yml is the primary template and asks for two commands and two outputs. Plus bug.yml, language.yml (pointed at the ten untested backends), and a config.yml chooser that routes feature requests upstream and security reports to private advisories.
.github/PULL_REQUEST_TEMPLATE.md Has a Parity section that forces the author to say which of the three cases the change is. Notes that make check does not run lint.

Also: a dead link in the parity docs

docs/parity.md offered test/integration/parity_report.json as the evidence behind the 78/78 number, but that path is in .gitignore — the report is generated, and CI uploads it as the parity-report artifact. A document whose entire argument is this is measured, not remembered cannot point at a 404, so it now points at the artifact that exists.

Verification

pre-commit run --all-files passes, including golangci-lint and check-yaml; all four issue-template YAML files parse.

Refs #43

Issue #43 asks what a port owes a reader who already uses the thing it
reimplements. Attribution, the name collision and the shared cache all
landed. The community health files did not, and their absence is the
part a prospective adopter notices first: no CONTRIBUTING, no SECURITY,
no issue templates, so every report arrives shaped however the reporter
guessed.

For this project that shape matters more than usual. The single most
valuable thing anyone can send is a divergence report -- upstream does
X, this does Y, both commands, both outputs -- because it is the one
class of bug the project cannot find for itself. So the divergence
template is the primary one and asks for exactly that pair, and both
CONTRIBUTING and the issue chooser say plainly that a feature upstream
lacks belongs on upstream's tracker, not here.

SECURITY draws the line where it actually falls for a hook runner: the
tool downloads and executes code by design, so the boundary is whose
code and whether it can be made to run something unasked -- checksum
verification in the action, path handling in the store, config parsing.
A hostile entry in your own config is not a vulnerability in the runner.

Also fixes a dead link. docs/parity.md offered
test/integration/parity_report.json as the evidence behind the parity
number, but that path is gitignored -- the file is generated, and CI
uploads it as an artifact. A doc whose whole argument is "this is
measured, not remembered" cannot point at a 404, so it now points at
the artifact that exists.

Refs #43
@blairham
blairham merged commit 9987e7c into main Sep 8, 2026
5 checks passed
@blairham
blairham deleted the launch-43 branch September 8, 2026 01:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant