Contributing
Development setup and workflow. The authoritative guide is the repository's CONTRIBUTING.md.
Development setup
python3.11 -m venv .venv && source .venv/bin/activate pip install -e '.[dev]' pytest
The test suite is hermetic: it runs against an isolated
HOME and never touches your real ~/.aiguard/.
Workflow
- Keep changes small and covered by tests; run
pytestbefore opening a pull request. - Use the domain vocabulary from
GLOSSARY.md— Decision, Action, Challenge, Approval, Guardrail — in code, docs, and commit messages. - Record significant design decisions as ADRs in
docs/adr/. - Update
CHANGELOG.mdunder Unreleased.
Security-sensitive changes
Changes to the policy engine, approval flow, TOTP, or file permissions are security-sensitive. If you believe you have found a vulnerability, do not open a public issue — report it privately per the security policy.
License
AIGuard is licensed under Apache-2.0. By contributing, you agree your contributions are licensed under the same terms.