From f750a79814489e17b56724675bf77ab970fc26da Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Fri, 14 Aug 2026 16:09:39 +0000 Subject: [PATCH] docs+ci: land #54 onboarding docs and align required CI checks Bring in MikeGatsby's CONTRIBUTING / CoC / PR template work from #63, complete the Contributor Covenant 2.1 enforcement guidelines, add a SemVer note, and make CI match the documented local commands (`ruff check src tests scripts`) with concurrency + least-privilege permissions so same-repo PRs get real check runs. Co-authored-by: MikeGatsby --- .github/PULL_REQUEST_TEMPLATE.md | 12 +++ .github/workflows/ci.yml | 13 ++- CODE_OF_CONDUCT.md | 134 +++++++++++++++++++++++++++++++ CONTRIBUTING.md | 98 ++++++++++++++++++++++ 4 files changed, 255 insertions(+), 2 deletions(-) create mode 100644 .github/PULL_REQUEST_TEMPLATE.md create mode 100644 CODE_OF_CONDUCT.md create mode 100644 CONTRIBUTING.md diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md new file mode 100644 index 0000000..bb9fd29 --- /dev/null +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -0,0 +1,12 @@ +## What this PR does + + + +Closes # + +## Checklist + +- [ ] Tests / ruff / sanitize pass locally (`pytest`, `ruff check src tests scripts`, `bash scripts/sanitize_check.sh`) +- [ ] No personal writing or paths (real LinkedIn exports, notes, emails, `/Users/you/...`) +- [ ] Contoso-safe docs/screenshots only — no real corpus samples +- [ ] Linked issue diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3bb2d28..7035682 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,6 +4,14 @@ on: push: branches: [main, master] pull_request: + types: [opened, synchronize, reopened, ready_for_review] + +concurrency: + group: ci-${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +permissions: + contents: read jobs: lint: @@ -19,7 +27,8 @@ jobs: python -m pip install --upgrade pip pip install -e ".[dev]" - name: Ruff - run: ruff check src tests + # Keep in sync with CONTRIBUTING.md local checks + run: ruff check src tests scripts test: name: test (${{ matrix.python }}) @@ -32,7 +41,7 @@ jobs: - uses: actions/checkout@v4 - uses: actions/setup-python@v5 with: - python-version: ${{ matrix.python }} + python-version: "${{ matrix.python }}" - name: Install run: | python -m pip install --upgrade pip diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..a4d2502 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,134 @@ +# Contributor Covenant Code of Conduct + +## Our Pledge + +We as members, contributors, and leaders pledge to make participation in our +community a harassment-free experience for everyone, regardless of age, body +size, visible or invisible disability, ethnicity, sex characteristics, gender +identity and expression, level of experience, education, socio-economic +status, nationality, personal appearance, race, caste, color, religion, or +sexual identity and orientation. + +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards + +Examples of behavior that contributes to a positive environment for our +community include: + +* Demonstrating empathy and kindness toward other people +* Being respectful of differing opinions, viewpoints, and experiences +* Giving and gracefully accepting constructive feedback +* Accepting responsibility and apologizing to those affected by our mistakes, + and learning from the experience +* Focusing on what is best not just for us as individuals, but for the + overall community + +Examples of unacceptable behavior include: + +* The use of sexualized language or imagery, and sexual attention or advances + of any kind +* Trolling, insulting or derogatory comments, and personal or political + attacks +* Public or private harassment +* Publishing others' private information, such as a physical or email + address, without their explicit permission +* Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Enforcement Responsibilities + +Community leaders are responsible for clarifying and enforcing our standards +of acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, +offensive, or harmful. + +Community leaders have the right and responsibility to remove, edit, or reject +comments, commits, code, wiki edits, issues, and other contributions that are +not aligned to this Code of Conduct, and will communicate reasons for +moderation decisions when appropriate. + +## Scope + +This Code of Conduct applies within all community spaces, and also applies +when an individual is officially representing the community in public spaces. +Examples of representing our community include using an official e-mail +address, posting via an official social media account, or acting as an +appointed representative at an online or offline event. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the community leaders responsible for enforcement by opening an +issue or contacting the maintainers directly via the TelivityAI organization +on GitHub. All complaints will be reviewed and investigated promptly and +fairly. + +All community leaders are obligated to respect the privacy and security of +the reporter of any incident. + +## Enforcement Guidelines + +Community leaders will follow these Community Impact Guidelines in determining +the consequences for any action they deem in violation of this Code of Conduct: + +### 1. Correction + +**Community Impact**: Use of inappropriate language or other behavior deemed +unprofessional or unwelcome in the community. + +**Consequence**: A private, written warning from community leaders, providing +clarity around the nature of the violation and an explanation of why the +behavior was inappropriate. A public apology may be requested. + +### 2. Warning + +**Community Impact**: A violation through a single incident or series of +actions. + +**Consequence**: A warning with consequences for continued behavior. No +interaction with the people involved, including unsolicited interaction with +those enforcing the Code of Conduct, for a specified period of time. This +includes avoiding interactions in community spaces as well as external +channels like social media. Violating these terms may lead to a temporary or +permanent ban. + +### 3. Temporary Ban + +**Community Impact**: A serious violation of community standards, including +sustained inappropriate behavior. + +**Consequence**: A temporary ban from any sort of interaction or public +communication with the community for a specified period of time. No public or +private interaction with the people involved, including unsolicited +interaction with those enforcing the Code of Conduct, is allowed during this +period. Violating these terms may lead to a permanent ban. + +### 4. Permanent Ban + +**Community Impact**: Demonstrating a pattern of violation of community +standards, including sustained inappropriate behavior, harassment of an +individual, or aggression toward or disparagement of classes of individuals. + +**Consequence**: A permanent ban from any sort of public interaction within +the community. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], +version 2.1, available at +[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1]. + +Community Impact Guidelines were inspired by +[Mozilla's code of conduct enforcement ladder][Mozilla CoC]. + +For answers to common questions about this code of conduct, see the FAQ at +[https://www.contributor-covenant.org/faq][FAQ]. Translations are available at +[https://www.contributor-covenant.org/translations][translations]. + +[homepage]: https://www.contributor-covenant.org +[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html +[Mozilla CoC]: https://github.com/mozilla/diversity +[FAQ]: https://www.contributor-covenant.org/faq +[translations]: https://www.contributor-covenant.org/translations diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..dfb4db1 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,98 @@ +# Contributing to PersonalityProtect + +Thanks for looking at this repo. This guide gets you from a fresh clone to a +green test run, and lays out the privacy rule that matters more than anything +else here. + +Based on the community onboarding work started in +[#63](https://github.com/TelivityAI/personality-protect/pull/63) by +[@MikeGatsby](https://github.com/MikeGatsby). + +## Setup + +```bash +git clone https://github.com/TelivityAI/personality-protect.git +cd personality-protect +python3 -m venv .venv +source .venv/bin/activate +pip install -e ".[dev]" +``` + +## Running checks locally + +```bash +pytest +ruff check src tests scripts +bash scripts/sanitize_check.sh +``` + +These must pass before you open a PR. They match the required CI jobs below. + +## What CI requires + +Every PR needs these checks green (job names from `.github/workflows/ci.yml`): + +- `lint` +- `test (3.11)` +- `test (3.12)` +- `sanitize` +- `cli-smoke` + +`sanitize` (`scripts/sanitize_check.sh`) fails the build if private paths or +discussion-only language leak into tracked files — see the privacy rule below +for what that covers. + +**First-time contributors:** GitHub holds Actions from new fork authors until a +maintainer clicks **Approve and run workflows** on the PR. That is expected, not +a missing workflow file. + +## Privacy — read this before you commit anything + +**Never commit:** + +- Your real LinkedIn export, emails, or personal notes +- Adapters, SFT JSONL, or eval drafts built from your own writing +- Profile URLs or personal file paths (e.g. `/Users/you/Dropbox/...`) +- Real before/after writing samples, in code, docs, or screenshots + +**Public docs and PRs use synthetic Contoso / synergy-slop text only.** If you +need an example, invent one the way the README does (`Contoso Ledger`, +`Contoso pricing`, etc.) — never paste anything from your own corpus. + +`.gitignore` already blocks profiles, adapters, SFT files, exports, weights, +and secrets, and `scripts/sanitize_check.sh` runs in CI as a second check on +tracked files. If `sanitize` fails your PR, it means one of those patterns +matched — fix the content, don't work around the check. + +## Trying the CLI without your own data + +You don't need a real corpus or a model download to explore the project: + +```bash +personality-protect demo +``` + +This runs a stubbed smoke tour of the `write` path with synthetic Contoso +content only — no download, no personal data required. + +## Versioning + +We use Semantic Versioning (`MAJOR.MINOR.PATCH`) in `pyproject.toml`. + +- Patch: bugfixes, docs, CI +- Minor: backward-compatible features +- Major: breaking CLI or package changes + +Tag releases as `vX.Y.Z` when cutting a PyPI publish (see #62). + +## Opening a PR + +- Keep changes scoped to what the linked issue describes. +- Link the issue you're addressing. +- Make sure `pytest`, `ruff check src tests scripts`, and + `bash scripts/sanitize_check.sh` pass locally first. +- Fill out the PR template checklist. + +## Code of Conduct + +This project follows the [Contributor Covenant](CODE_OF_CONDUCT.md).