Skip to content

v0.7.1 — CONTRIBUTING.md + SECURITY.md

Choose a tag to compare

@PeterGuy326 PeterGuy326 released this 10 May 15:16
· 10 commits to main since this release

[0.7.1] - 2026-05-10

Community-health files added — CONTRIBUTING.md and SECURITY.md. No skill changes; these are the files the skills already referenced (pr-review Step 1/Step 6, issue-triage Step 0/Step 1, hotfix-flow, release-sop Step 2). Patch release.

Added

  • CONTRIBUTING.md — contributor guide — codifies the two hard rules (one skill per directory, ecosystem-agnostic core), what shipping a new skill entails (SKILL.md + examples/<name>-demo.md + README rows + CHANGELOG entry; install.sh auto-discovers), the PR conventions pr-review checks (title type(scope): summary, What/Why + linked issue, tests/CHANGELOG/docs same-PR, CHANGELOG goes in [Unreleased] not a tag commit — pointer to changelog-bot, Breaking + migration line, the security flag), local-testing steps (./install.sh <skill> → restart Claude Code), and the release / hotfix procedure (release-sop / hotfix-flow; tag is the only release trigger; main is protected, all changes via PR). Previously these rules lived only as a two-line section in the README.
  • SECURITY.md — security policy — supported versions (latest release only; upgrade before reporting), what counts as a security issue for a docs/skill repo (a SKILL.md that could be steered to do harm or skip a gate; install.sh filesystem surprises; supply-chain of the raw-URL install path) vs. an ordinary bug, how to report privately (GitHub private vulnerability reporting via the Security tab — no public issues/PRs/discussions with details or PoCs), what to expect (acknowledgement, fix-or-written-decision, hotfix-flow for fixes that can't wait, coordinated disclosure with an advisory naming affected versions, credit), and how it ties into the skills (issue-triage routes here, pr-review Step 6 requires this flow, hotfix-flow runs security fixes through it). pr-review, issue-triage, hotfix-flow, and release-sop all reference SECURITY.md; this is the file they were referencing.
  • README.md — Contributing section points to CONTRIBUTING.md / SECURITY.md; layout tree updated — the Contributing section keeps the two-line rule summary and now links the full CONTRIBUTING.md and SECURITY.md, plus notes main is protected; the repo-layout tree gains CONTRIBUTING.md and SECURITY.md rows.