docsloth.org
Contribute
Components and contracts live in the Apache-2.0 repository; the engine is AGPL-3.0-only. Contributions are accepted under a Developer Certificate of Origin, and you keep your copyright.
Where contributions land
- A new component
- Add a prop schema, a manifest fixture, an implementation for its trust class, documentation and behaviour/a11y tests. The Forge flow scaffolds this, and the registry accepts packages from any source, not only the hosted marketplace.
- An extractor or grammar
- Extractors declare their tier. Native grammars must run behind the parser interface and report unsupported constructs rather than guessing; degraded extractors are labelled as such in every report.
- A provider adapter
- Implement the model, resource, sandbox, storage, deployment or analytics interface, negotiate capabilities honestly, and add fixtures. Never silently fall back to a fake provider.
- A fix
- Include a regression test. Security fixes are never gated behind a paid plan and are backported to supported releases.
Rules that are not negotiable
- No fabricated measurements, testimonials, certifications or support promises.
- Untrusted input (repositories, issues, model output) is data, never instructions.
- Do not weaken tenant isolation, capability checks or budget enforcement to make a feature easier.
- Licence boundaries are structural: no AGPL code inside the permissive browser packages.
Actions
Actions
- Choose issue
Opens the channel list. No issue tracker URL is configured in this build, so nothing is invented; the community page states exactly which channels exist.
- Run checks
Shows the real local setup. In this repository the gates are npx vitest run, npx tsc --noEmit -p tsconfig.json, npm run lint and npx next build; run the equivalents in the repository you changed.
- Sign off commit
Contributions are accepted under a Developer Certificate of Origin; sign off with git commit -s, and you keep your copyright.