Skip to content

docs: CONTRIBUTING owns process; SECURITY.md; ignore .vs - #762

Merged
tylerkron merged 4 commits into
mainfrom
cursor/contributing-owns-process-6cac
Sep 27, 2026
Merged

tylerkron merged 4 commits into
mainfrom
cursor/contributing-owns-process-6cac

Conversation

@tylerkron

@tylerkron tylerkron commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

What was wrong

  • CONTRIBUTING never said how a change actually lands. It told you to open a PR and then
    stopped. The rules that actually gate main (the merge queue, squash-only, the PR title
    becoming the commit message) were written down only in the agent rule files, which a human
    contributor never reads.
  • The one statement it did make about merging was wrong. "The PR needs review before merge"
    describes a repo with required approvals. This one requires zero (solo maintainer). What it
    does require is that every review conversation be resolved. That's the gate people
    actually run into, and nothing said so.
  • The security policy was buried in CONTRIBUTING, so GitHub's Security tab had no policy
    to show and GitHub's own security-policy links had nothing to point at.
  • .vs/ wasn't ignored, so opening the solution in Visual Studio left a dirty tree.

How it was fixed

  • CONTRIBUTING.md: a short "How main is gated" section written from the live ruleset
    and repo merge settings:

    • merge queue, with build as the required check;
    • squash-only. The commit title is the PR title plus (#N), and the body holds only
      GitHub's Co-authored-by: trailers;
    • zero required approvals, but every review thread must be resolved. Replying alone
      doesn't clear it.

    Step 4 now says the same thing. It also notes that the agent rule files defer to
    CONTRIBUTING, and that CONTRIBUTING wins if they ever disagree.

  • SECURITY.md: the existing security paragraph moved out of CONTRIBUTING unchanged, so
    GitHub picks it up. No contact, response time or supported-version promise was added. The
    private-report route is still the one the file already named (daqifi.com).

  • README.md: CONTRIBUTING and SECURITY links under "Community & support". They are
    absolute github.com/.../blob/main/... URLs because README.md is also the nuget.org package
    readme, where relative links 404.

  • .gitignore: .vs/ added to the existing "User-specific files" block (VS keeps *.suo
    there too) rather than opening a fourth VS-related section.

.cursor/rules/daqifi-core.mdc and .claude/rules/git-workflow.md are untouched. They landed
in #735 and #754 after this PR opened, both already say CONTRIBUTING owns the contributor
process, and their short restatement of the gating matches the section added here.

Docs and process only. No C# and no build inputs changed.

🤖 Generated with Claude Code

cursoragent and others added 2 commits September 20, 2026 10:29
Fill the deferred how-main-is-gated gap (merge queue, squash-only, type(scope) titles) in CONTRIBUTING so agent files can point there instead of being a second source of truth. Move the security paragraph to SECURITY.md and ignore Visual Studio's .vs/ folder.

Co-authored-by: Tyler Kron <tylerkron@gmail.com>
…lock

Review follow-ups on this PR:

- CONTRIBUTING still said a PR "needs review before merge". main's ruleset
  requires zero approving reviews (solo maintainer) but does require every
  review conversation to be resolved, which is the gate people actually hit.
  Both statements now match the live ruleset.
- The PR-title bullet claimed "!" as observed practice; no commit in the log
  uses it, so it now reads as the convention to follow.
- .vs/ got its own "# Visual Studio" heading beside three existing
  VS-related sections. It is the per-user solution cache, so it goes in the
  existing "User-specific files" block next to *.suo, which lives inside it.
- Moved the CONTRIBUTING/SECURITY links from "For maintainers" to
  "Community & support", where a would-be contributor is actually looking.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@tylerkron

Copy link
Copy Markdown
Contributor Author

/agentic_review

@qodo-code-review

qodo-code-review Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can describe a rule in plain language on the Rules page and Qodo drafts it for you

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Previous reviews

Review updated until commit 9ac7051 🧠 Deep

Results up to commit ef35e21 ⏭️ Skipped


No changes from previous review

Grey Divider

Qodo Logo

@tylerkron
tylerkron marked this pull request as ready for review September 21, 2026 01:34
@tylerkron
tylerkron requested a review from a team as a code owner September 21, 2026 01:34
@qodo-code-review

Copy link
Copy Markdown

Code review by qodo was updated up to the latest commit ef35e21

@tylerkron

Copy link
Copy Markdown
Contributor Author

Reviewed (Claude): approved after fixes — every process claim was checked against the live ruleset (merge queue on, required check build, squash-only with PR_TITLE/BLANK). Two things the PR left wrong: CONTRIBUTING still said a PR "needs review before merge" (the ruleset requires zero approvals but does require all review threads resolved — now stated correctly), and .vs/ got its own heading beside three existing VS sections, so it moved into the existing user-specific block. SECURITY.md is a verbatim move of the existing paragraph — no invented contact, SLA or supported-version policy. Qodo-clean on ef35e21, CI green — ready for review.

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Document repository merge gates and add security policy

📝 Documentation ⚙️ Configuration changes 🕐 10-20 Minutes

Grey Divider

AI Description

• Documents merge-queue, review-thread, squash, and PR-title requirements for main.
• Moves vulnerability reporting guidance into GitHub-discoverable SECURITY.md and links both
 policies.
• Ignores Visual Studio's per-user .vs directory.
Diagram

graph TD
  C["Contributor"] --> R["README"] --> G["Contribution Guide"] --> P["Pull Request"] -->|"build and threads"| Q["Merge Queue"] -->|"squash title"| M["main"]
  R --> S["Security Policy"]
Loading
High-Level Assessment

The approach is appropriate: CONTRIBUTING.md becomes the human-facing source of truth for merge rules, while a root SECURITY.md enables GitHub's native security-policy discovery. Keeping agent rules unchanged avoids overlapping with separately tracked work, and placing .vs/ beside other user-specific Visual Studio artifacts preserves the existing ignore structure.

Files changed (4) +41 / -13

Documentation (3) +40 / -13
CONTRIBUTING.mdMake contribution guidance authoritative for merge gates +25/-13

Make contribution guidance authoritative for merge gates

• Documents the merge queue, required 'build' check, resolved-thread requirement, squash-only behavior, and conventional PR-title format. Replaces the inaccurate approval requirement and delegates security guidance to SECURITY.md.

CONTRIBUTING.md

README.mdSurface contribution and security policies +2/-0

Surface contribution and security policies

• Adds links under Community & support so contributors can discover merge-process guidance and private vulnerability reporting instructions.

README.md

SECURITY.mdPublish a GitHub-discoverable security policy +13/-0

Publish a GitHub-discoverable security policy

• Moves the existing patch-safety and private vulnerability-reporting guidance into a root security policy that GitHub can surface through its security interfaces.

SECURITY.md

Other (1) +1 / -0
.gitignoreIgnore Visual Studio's per-user solution cache +1/-0

Ignore Visual Studio's per-user solution cache

• Adds '.vs/' to the existing user-specific files block so opening the solution in Visual Studio does not dirty the working tree.

.gitignore

tylerkron and others added 2 commits September 27, 2026 10:36
…leset

README.md is packed as the nuget.org PackageReadmeFile, where relative links 404, so the new CONTRIBUTING/SECURITY links are absolute GitHub URLs. In CONTRIBUTING: replying to a review thread does not clear the conversation-resolution gate, only resolving it does; the squash commit is the PR title plus (#N) with only Co-authored-by trailers in the body; and the agent rule files (#735, #754, now landed) already defer here, so say that instead of asking them to stop restating the process.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@tylerkron

Copy link
Copy Markdown
Contributor Author

/agentic_review

@qodo-code-review

Copy link
Copy Markdown

Code review by qodo was updated up to the latest commit 9ac7051

@tylerkron

Copy link
Copy Markdown
Contributor Author

Qodo-clean, CI green — ready for review

@tylerkron
tylerkron added this pull request to the merge queue Sep 27, 2026
Merged via the queue into main with commit a299890 Sep 27, 2026
4 checks passed
@tylerkron
tylerkron deleted the cursor/contributing-owns-process-6cac branch September 27, 2026 17:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants