CONTRIBUTING.md (2497B)
1 # Contributing 2 3 Radroots SDK changes are contract-driven and independently verifiable. Before 4 editing, read `AGENTS.md`, then inspect the affected source lock, contracts, 5 package manifests, tools, generated outputs, and tests. 6 7 This repository is the public generated-package and source-lock consumer for 8 the Radroots SDK cohort. Canonical generator and Rust implementation source is 9 selected from `radrootslabs/lib` by the exact revision in 10 `radroots.lib.source-lock.v1.toml` and `Cargo.toml`. Human architecture and 11 execution authority is parent-owned under `docs/oss/sdk/**`; standalone 12 commands do not require that private parent documentation. 13 14 ## Workflow 15 16 1. Inspect repository status and the current machine authority. 17 2. Make one coherent, commit-sized change at the owning contract, tool, 18 generated-output, or package boundary. 19 3. If producer behavior changes, update the selected public lib source first, 20 then regenerate every affected SDK output from that exact reachable 21 revision. 22 4. Update contracts, tests, generated outputs, package metadata, and lockfiles 23 together. 24 5. Run the narrowest repository-owned checks that prove the change, followed 25 by the complete affected standalone lane. 26 6. Review the staged diff for source-lock drift, handwritten generated output, 27 stale provenance, private dependencies, forbidden roots, secrets, and 28 unrelated changes. 29 30 Run `cargo extbuild doctor` before the first mutating verification command and 31 route repository checks through `cargo extbuild run -- ...`. The primary 32 commands are: 33 34 ```text 35 pnpm run contracts:check 36 pnpm run boundaries:check 37 pnpm run test:tools 38 pnpm run source:check 39 pnpm run check 40 ``` 41 42 The source and generation lanes require an absolute, canonical 43 `RADROOTS_LIB_SOURCE_ROOT` whose Git revision matches the checked-in source 44 lock. The contract and tool-test lanes remain usable without the parent 45 monorepo. This capsule has no local `cargo xtask` package. 46 47 ## Commits and external actions 48 49 Use `<scope>: <lower-case imperative summary>` for focused commits. Do not add 50 capsule-local human authority, `.github/**`, or `.act/**`; do not create a 51 compatibility path for a breaking generated contract. Record any required 52 normative decision in the parent-owned services-hardening authority and update 53 the corresponding standalone machine contract. 54 55 Do not push, tag, publish, deploy, change registry ownership or trusted 56 publishers, or perform credential operations without separate explicit 57 authorization.