mirror of
https://github.com/SquidSec/SquidC5
synced 2026-08-09 12:22:26 +00:00
Org Default runner group no longer allows public repos. Move CI/SquidGate to ubuntu-latest/windows-latest and pin third-party actions to commit SHAs (org sha_pinning_required). Document protected master + CI posture.
2.7 KiB
2.7 KiB
Contributing to SquidC5
Authorized red-team / security research use only. Do not open issues or PRs that request help with unauthorized access.
Development cycle (required)
- Update
master(git pull). - Create a feature branch for one logical change.
- Write unit tests first.
- Implement the change.
- Red-green-refactor until
pytest -qandruff check src testspass. - Push the branch (never commit directly to
master). - Open a pull request into
master. - Wait for CI (tests, security, SquidGate when configured).
- Merge only when green.
- Start the next change from step 1.
Prefer small PRs. One fix or feature per cycle.
Local setup
python3 -m venv .venv && source .venv/bin/activate
pip install -r requirements-dev.txt && pip install -e .
pytest -q
ruff check src tests
Security rules
- Do not weaken MCP allow-lists, Admin AI
sanitize_untrusted, empty CORS default, or thepublic_docslock. - Never commit secrets,
data/, tokens, or API keys. - New endpoints require auth and appropriate scopes.
- Admin UI/JS (
/api/v1/ops/admin.js) must stay admin-gated on the server.
CI
- CI workflow: pytest (3.11/3.12), ruff, Docker smoke, pip-audit; Linux/Windows binaries + GitHub Release on push to
master. - Public SquidC5 CI uses GitHub-hosted runners (
ubuntu-latest/windows-latest). Org self-hosted runners do not accept public repos. - Actions are SHA-pinned; fork PR jobs that touch secrets are still gated to same-repo PRs. Fork contributors: run the local checks above and note results in the PR.
masteris protected: PR required, status checks (test (3.12),security), no force-push.- SquidGate (when configured): optional PR security gate. Repository secret
LLM_API_KEYenables full analysis when available.
Docs
Catalog and section templates: docs/README.md (Diátaxis: tutorials/how-tos vs reference vs explanation).
| Doc | Role |
|---|---|
| AGENTS.md | Agent memory + full CLI surface |
| docs/user-guide.md | Feature reference (What/Why/How/Example) |
| docs/operator-runbook.md | Day-2 procedures |
| docs/deployment.md | Lab + prod binary |
| docs/squidc5-vision.md | Architecture |
| docs/roadmap-2026-2027.md | Long-range roadmap |
| docs/prod-readiness-plan.md | Engineering checklist |
When you change operator-facing behavior, update the matching user-guide chapter and fix cross-links.
Pull requests
Use the PR template. Include:
- What changed and why
- Test plan (commands run)
- Security impact notes when relevant