docs: CONTRIBUTING owns process; SECURITY.md; ignore .vs - #762
Conversation
Fill the deferred how-main-is-gated gap (merge queue, squash-only, type(scope) titles) in CONTRIBUTING so agent files can point there instead of being a second source of truth. Move the security paragraph to SECURITY.md and ignore Visual Studio's .vs/ folder. Co-authored-by: Tyler Kron <tylerkron@gmail.com>
…lock Review follow-ups on this PR: - CONTRIBUTING still said a PR "needs review before merge". main's ruleset requires zero approving reviews (solo maintainer) but does require every review conversation to be resolved, which is the gate people actually hit. Both statements now match the live ruleset. - The PR-title bullet claimed "!" as observed practice; no commit in the log uses it, so it now reads as the convention to follow. - .vs/ got its own "# Visual Studio" heading beside three existing VS-related sections. It is the per-user solution cache, so it goes in the existing "User-specific files" block next to *.suo, which lives inside it. - Moved the CONTRIBUTING/SECURITY links from "For maintainers" to "Community & support", where a would-be contributor is actually looking. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
/agentic_review |
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can describe a rule in plain language on the Rules page and Qodo drafts it for you |
|
Code review by qodo was updated up to the latest commit ef35e21 |
|
Reviewed (Claude): approved after fixes — every process claim was checked against the live ruleset (merge queue on, required check |
PR Summary by QodoDocument repository merge gates and add security policy
AI Description
Diagram
High-Level Assessment
Files changed (4)
|
…leset README.md is packed as the nuget.org PackageReadmeFile, where relative links 404, so the new CONTRIBUTING/SECURITY links are absolute GitHub URLs. In CONTRIBUTING: replying to a review thread does not clear the conversation-resolution gate, only resolving it does; the squash commit is the PR title plus (#N) with only Co-authored-by trailers in the body; and the agent rule files (#735, #754, now landed) already defer here, so say that instead of asking them to stop restating the process. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
/agentic_review |
|
Code review by qodo was updated up to the latest commit 9ac7051 |
|
Qodo-clean, CI green — ready for review |
What was wrong
stopped. The rules that actually gate
main(the merge queue, squash-only, the PR titlebecoming the commit message) were written down only in the agent rule files, which a human
contributor never reads.
describes a repo with required approvals. This one requires zero (solo maintainer). What it
does require is that every review conversation be resolved. That's the gate people
actually run into, and nothing said so.
to show and GitHub's own security-policy links had nothing to point at.
.vs/wasn't ignored, so opening the solution in Visual Studio left a dirty tree.How it was fixed
CONTRIBUTING.md: a short "How
mainis gated" section written from the live rulesetand repo merge settings:
buildas the required check;(#N), and the body holds onlyGitHub's
Co-authored-by:trailers;doesn't clear it.
Step 4 now says the same thing. It also notes that the agent rule files defer to
CONTRIBUTING, and that CONTRIBUTING wins if they ever disagree.
SECURITY.md: the existing security paragraph moved out of CONTRIBUTING unchanged, so
GitHub picks it up. No contact, response time or supported-version promise was added. The
private-report route is still the one the file already named (daqifi.com).
README.md: CONTRIBUTING and SECURITY links under "Community & support". They are
absolute
github.com/.../blob/main/...URLs because README.md is also the nuget.org packagereadme, where relative links 404.
.gitignore:.vs/added to the existing "User-specific files" block (VS keeps*.suothere too) rather than opening a fourth VS-related section.
.cursor/rules/daqifi-core.mdcand.claude/rules/git-workflow.mdare untouched. They landedin #735 and #754 after this PR opened, both already say CONTRIBUTING owns the contributor
process, and their short restatement of the gating matches the section added here.
Docs and process only. No C# and no build inputs changed.
🤖 Generated with Claude Code