mirror of
https://github.com/SquidSec/SquidC5
synced 2026-08-09 12:22:26 +00:00
1.6 KiB
1.6 KiB
Contributing to SquidC5
Authorized red-team / security research use only. Do not open issues or PRs that request help with unauthorized access.
Development cycle (required)
- Update
master(git pull). - Create a feature branch for one logical change.
- Write unit tests first.
- Implement the change.
- Red-green-refactor until
pytest -qandruff check src testspass. - Push the branch (never commit directly to
master). - Open a pull request into
master. - Wait for CI (tests, security, SquidGate when configured).
- Merge only when green.
- Start the next change from step 1.
Prefer small PRs. One fix or feature per cycle.
Local setup
python3 -m venv .venv && source .venv/bin/activate
pip install -r requirements-dev.txt && pip install -e .
pytest -q
ruff check src tests
Security rules
- Do not weaken MCP allow-lists, Admin AI
sanitize_untrusted, empty CORS default, or thepublic_docslock. - Never commit secrets,
data/, tokens, or API keys. - New endpoints require auth and appropriate scopes.
- Admin UI/JS (
/api/v1/ops/admin.js) must stay admin-gated on the server.
CI
- CI workflow: pytest (3.11/3.12), ruff, Docker smoke, pip-audit, binaries on
master. - SquidGate (
SquidSec/SquidGate@v1.0.0-build.4): PR security gate. Set repository secretLLM_API_KEYto enable full analysis.
Docs
- Operator/agent memory:
AGENTS.md - Vision and roadmap:
docs/ - Prod-readiness execution plan:
docs/prod-readiness-plan.md
Pull requests
Use the PR template. Include:
- What changed and why
- Test plan (commands run)
- Security impact notes when relevant