Public source file

CONTRIBUTING.md

Documentation home
73 lines1,719 bytesread-only generated view
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
# Contributing

This repository is scoped to a public QR verifier reference PoC. Contributions
should improve implementation clarity, reproducibility, security posture, test
coverage, or public documentation.

## Public Repo Boundary

Do not add:

- private filing materials
- patent prosecution notes
- personal contact details beyond intentional public metadata
- real API keys, tokens, passwords, private keys, or customer identifiers
- production credentials or screenshots containing credentials

Use `private/`, `archive/`, `local/`, or your own ignored workspace for local
material that should not be public.

## Useful Commands

Run the narrowest relevant checks before opening a pull request:

```bash
make release-audit
make smoke-compose
make build-frontend
make smoke-ios
```

For backend changes:

```bash
cd backend
PYTHONPATH=.. ./.venv/bin/pytest
```

For frontend changes:

```bash
cd frontend
npm run build
```

For physical iPhone evidence, add the artifacts first and run:

```bash
make check-iphone-evidence
```

## Pull Request Expectations

Each pull request should state:

- what verifier behavior or documentation changed
- which commands were run
- whether public-release boundaries changed
- whether screenshots, PDFs, or generated artifacts were added
- whether the change affects browser, backend, compose, or native iPhone flows

## Design Principles

Prefer changes that keep the PoC:

- deterministic
- explainable to students, researchers, and engineers
- narrow enough to audit
- explicit about what is verified versus only documented
- honest about non-production assumptions

Avoid broad claims that the project is a standard, a complete governance model,
or proof of patentability.