Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
71 changes: 71 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
name: Bug report
description: Something in the Codex integration behaves incorrectly
labels: ["bug"]
body:
- type: markdown
attributes:
value: |
Thanks for the report. This repository is the **Codex integration surface**
(MCP server wiring, the `signetry guard` lifecycle hook, `config.toml`).
Governance logic — contract evaluation, guard decisions, the verifier, receipts —
lives in [signetry-core](https://github.com/Signetry/core); please file those
there.

For a **security vulnerability**, do not open an issue: use
[private vulnerability reporting](https://github.com/Signetry/github-app/security/advisories/new)
instead. See [SECURITY.md](https://github.com/Signetry/github-app/blob/main/SECURITY.md).

- type: textarea
id: what-happened
attributes:
label: What happened
description: What you saw, and what you expected instead.
validations:
required: true

- type: textarea
id: repro
attributes:
label: Steps to reproduce
description: The smallest sequence that shows the problem.
placeholder: |
1. Wired the MCP server into ~/.codex/config.toml as documented
2. Asked Codex to ...
3. Observed ...
validations:
required: true

- type: textarea
id: config
attributes:
label: Relevant config
description: >
Your `~/.codex/config.toml` Signetry block and/or `.signetry/admission.yaml`.
Redact anything private — never paste an API key.
render: toml

- type: textarea
id: output
attributes:
label: Command output
description: >
Output from the failing command (e.g. `signetry guard ...`), or the Codex
transcript around the failure.
render: shell

- type: input
id: core-version
attributes:
label: signetry-core version
description: The pin you installed (e.g. `v0.7.0`), or the output of `signetry --version`.
validations:
required: true

- type: input
id: env
attributes:
label: Environment
description: OS, Python version, Codex version.
placeholder: macOS 15.3, Python 3.12.4, Codex CLI 0.x
validations:
required: true
13 changes: 13 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
blank_issues_enabled: true
contact_links:
- name: Governance engine (signetry-core)
url: https://github.com/Signetry/core/issues
about: >
Contract evaluation, guard decisions, the verifier, receipts, and scanning live
in the engine. File engine behaviour there, not here.
- name: Signetry platform overview
url: https://github.com/Signetry/signetry
about: How the integrations, the engine, and the CI action fit together.
- name: Report a security vulnerability (private)
url: https://github.com/Signetry/github-app/security/advisories/new
about: Signetry is a security tool. Please report privately, never in a public issue.
43 changes: 43 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
name: Feature request
description: Suggest an improvement to the Codex integration
labels: ["enhancement"]
body:
- type: markdown
attributes:
value: |
This repository is Apache-2.0 and contributions are welcome — see
[CONTRIBUTING.md](https://github.com/Signetry/github-app/blob/main/CONTRIBUTING.md).

Scope check: this repo wires Codex to the engine. It **never reimplements
policy** and never auto-merges. Requests to change how contracts are
evaluated, how receipts are signed, or what the guard decides belong in
[signetry-core](https://github.com/Signetry/core).

- type: textarea
id: problem
attributes:
label: The problem
description: What are you trying to do that this integration makes hard or impossible today?
validations:
required: true

- type: textarea
id: proposal
attributes:
label: Proposed change
description: What should the integration do instead? Config snippets welcome.
validations:
required: true

- type: textarea
id: alternatives
attributes:
label: Alternatives considered
description: Workarounds you tried, and why they were not enough.

- type: checkboxes
id: contribute
attributes:
label: Would you like to implement this?
options:
- label: I'm willing to open a pull request (I'll sign the CLA).
6 changes: 4 additions & 2 deletions .github/workflows/cla.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,9 @@ name: CLA
# before their pull request can be merged. Runs entirely in this repo's Actions —
# no third-party OAuth app. Signatures are recorded in signatures/cla.json on this
# repo, so there is a durable, auditable record that each contributor assigned
# copyright/ownership of their contribution to the Owner.
# copyright in their contribution to the Owner — which is what lets code be
# relicensed across the open-core line (BUSL-1.1 engine <-> Apache-2.0 integrations)
# without re-asking every past contributor.
#
# A contributor signs by commenting the exact statement below on their PR:
# I have read the CLA Document and I hereby sign the CLA
Expand Down Expand Up @@ -48,7 +50,7 @@ jobs:
path-to-document: "https://github.com/Signetry/github-app/blob/main/CLA.md"
branch: "cla-signatures"
allowlist: "dependabot[bot],bkd-dotcom"
custom-notsigned-prcomment: "Thanks for your contribution! Before it can be merged, please read the **[Contributor License Agreement](https://github.com/Signetry/github-app/blob/main/CLA.md)** — Signetry is **All Rights Reserved**, and by signing you assign copyright/ownership of your contribution to the Owner (you may not use, sell, or commercialize it yourself). To agree, reply with exactly:"
custom-notsigned-prcomment: "Thanks for your contribution! Before it can be merged, please read the **[Contributor License Agreement](https://github.com/Signetry/github-app/blob/main/CLA.md)** — Signetry is **open core** (this repo is Apache-2.0; the engine is BUSL-1.1, converting to Apache-2.0 on 2030-08-31). Signing assigns copyright in your contribution to the Owner so code can be relicensed across that open-core line later without re-asking every contributor. It does not take away the rights the LICENSE already grants you. To agree, reply with exactly:"
custom-pr-sign-comment: "I have read the CLA Document and I hereby sign the CLA"
custom-allsigned-prcomment: "All contributors have signed the CLA. ✅"
lock-pullrequest-aftermerge: false
2 changes: 1 addition & 1 deletion .github/workflows/reviewer.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ jobs:
with:
python-version: "3.12"
- name: Install signetry-reviewer
# source-available (All Rights Reserved); install from source, not PyPI.
# not published to PyPI — install from its source repo by tag.
run: pip install "signetry-reviewer @ git+https://github.com/Signetry/reviewer@v0.2.0"
- name: Compute the PR diff
env:
Expand Down
22 changes: 22 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,28 @@ Follows [Keep a Changelog](https://keepachangelog.com/) / [SemVer](https://semve

## [Unreleased]

### Changed — Signetry is now open core; this repo is Apache-2.0

- An [Apache-2.0](LICENSE) **LICENSE** file is now present, replacing the previous
"All Rights Reserved" terms, as part of Signetry's
[open-core model](https://github.com/Signetry/signetry/blob/main/LICENSING.md). The
integration surface is Apache-2.0 — fork the App, run your own instance, ship it
commercially — while the engine
([`Signetry/core`](https://github.com/Signetry/core)) is source-available under
BUSL-1.1 and converts to Apache-2.0 on 2030-08-31.
- The all-rights-reserved framing is gone from `README.md`, `CONTRIBUTING.md`,
`CLA.md`, `CONTRIBUTORS.md`, and the CLA workflow's PR comment.
- `CONTRIBUTING.md` now states the two properties any change here must preserve: the
App is **comment-only**, and its comment never claims more than the signed receipt
does.
- **The CLA is kept**, and its fallback licence grant is now **non-exclusive** so a
contributor never loses the right to use their own contribution. See
[CLA.md](CLA.md) §2–3.

### Added — community health files

- `CODE_OF_CONDUCT.md` (Contributor Covenant v2.1) and GitHub issue templates.

### Changed

- Signetry naming across docs, the app manifest display fields, and the reviewer
Expand Down
38 changes: 27 additions & 11 deletions CLA.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,10 @@
# Signetry Contributor License Agreement (CLA)

**Copyright (c) 2026 Binay Dalai. All rights reserved.**
**Copyright (c) 2026 Binay Dalai.** This repository is licensed under
**[Apache-2.0](LICENSE)** as part of Signetry's
[open-core model](https://github.com/Signetry/signetry/blob/main/LICENSING.md). This
Agreement governs what You grant the Owner when You contribute; it does not reduce the
rights the Apache-2.0 licence gives You (and everyone else) in this code.

Thank you for your interest in contributing to Signetry ("the Project"), owned by
Binay Dalai ("the Owner"). This Contributor License Agreement ("Agreement")
Expand All @@ -26,21 +30,33 @@ Your Contribution. You agree that the Owner is the sole and exclusive owner of t
Contribution once merged into the Project.

To the extent any rights cannot be assigned by law, You grant the Owner a
**perpetual, worldwide, exclusive, irrevocable, royalty-free, sublicensable, and
**perpetual, worldwide, non-exclusive, irrevocable, royalty-free, sublicensable, and
transferable license** to use, reproduce, modify, prepare derivative works of,
publicly display, publicly perform, distribute, **sell, and commercialize** Your
Contribution, in whole or in part, in any form and for any purpose.

## 3. The Owner's exclusive rights
Nothing in this section removes Your own ability to use Your Contribution: once it is
released as part of this repository it is available to You, as to anyone, under
[Apache-2.0](LICENSE), and You retain any rights You independently hold in the
underlying ideas and techniques.

## 3. Why the Owner needs this (open core)

You acknowledge and agree that:

- The Owner alone retains the right to **use, license, sell, and monetize** the
Project, including Your Contribution.
- You obtain **no right** to use, copy, modify, distribute, sell, or commercialize
the Project or Your Contribution for Your own personal or commercial purposes,
except as expressly permitted in writing by the Owner.
- The Project is **not open source** and is licensed "All Rights Reserved."
- **You keep the licence's rights.** This repository is released under
[Apache-2.0](LICENSE), so You may use, copy, modify, distribute, and commercialize
it — including Your own Contribution — on exactly the same terms as any other user.
No separate written permission is required.
- **The Owner may relicense.** The assignment above lets the Owner use, license, sell,
and monetize the Project, including Your Contribution, and release it under other
terms.
- **Code may move across the open-core line.** Signetry's integration surface is
Apache-2.0 while the engine
([`Signetry/core`](https://github.com/Signetry/core)) is source-available under
BUSL-1.1, converting to Apache-2.0 on 2030-08-31. A Contribution accepted here may
later be moved into the engine, or engine code moved out to an Apache-2.0 repo. The
CLA is what makes that possible without asking every past contributor again.

## 4. Recognition of Contributors (credit, not rights)

Expand All @@ -50,8 +66,8 @@ of Your work.

This recognition is **attribution only**. It does **not**:

- grant You any ownership, license, or right to use, copy, sell, sublicense, or
commercialize the Project or Your Contribution;
- grant You ownership of the Project, or any rights beyond those the Project's
licence already grants everyone;
- entitle You to represent the Project, or any part of it, as Your own work, product,
or property, or to market or sell it under Your own name or brand; or
- create any partnership, employment, or revenue-sharing relationship with the Owner.
Expand Down
68 changes: 68 additions & 0 deletions CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
# Contributor Covenant Code of Conduct

## Our Pledge

We as members, contributors, and leaders pledge to make participation in our
community a harassment-free experience for everyone, regardless of age, body
size, visible or invisible disability, ethnicity, sex characteristics, gender
identity and expression, level of experience, education, socio-economic status,
nationality, personal appearance, race, religion, or sexual identity and
orientation.

We pledge to act and interact in ways that contribute to an open, welcoming,
diverse, inclusive, and healthy community.

## Our Standards

Examples of behavior that contributes to a positive environment for our
community include:

- Demonstrating empathy and kindness toward other people
- Being respectful of differing opinions, viewpoints, and experiences
- Giving and gracefully accepting constructive feedback
- Accepting responsibility and apologizing to those affected by our mistakes,
and learning from the experience
- Focusing on what is best not just for us as individuals, but for the overall
community

Examples of unacceptable behavior include:

- The use of sexualized language or imagery, and sexual attention or advances of
any kind
- Trolling, insulting or derogatory comments, and personal or political attacks
- Public or private harassment
- Publishing others' private information, such as a physical or email address,
without their explicit permission
- Other conduct which could reasonably be considered inappropriate in a
professional setting

## Enforcement Responsibilities

Community leaders are responsible for clarifying and enforcing our standards of
acceptable behavior and will take appropriate and fair corrective action in
response to any behavior that they deem inappropriate, threatening, offensive,
or harmful.

## Scope

This Code of Conduct applies within all community spaces, and also applies when
an individual is officially representing the community in public spaces.

## Enforcement

Instances of abusive, harassing, or otherwise unacceptable behavior may be
reported to the maintainers via
[GitHub private vulnerability reporting](https://github.com/Signetry/github-app/security/advisories/new)
or by opening a confidential issue. All complaints will be reviewed and
investigated promptly and fairly.

All community leaders are obligated to respect the privacy and security of the
reporter of any incident.

## Attribution

This Code of Conduct is adapted from the [Contributor Covenant][homepage],
version 2.1, available at
<https://www.contributor-covenant.org/version/2/1/code_of_conduct.html>.

[homepage]: https://www.contributor-covenant.org
55 changes: 47 additions & 8 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,42 @@
# Contribution Agreement
# Contributing to the Signetry GitHub App

By submitting a Pull Request to this repository, you agree to assign and transfer all copyright and ownership of your contributed code to the repository owner. The owner retains the exclusive right to monetize, use, and control the entire codebase.
Contributions are welcome — the App manifest, the setup docs, and the comment
rendering are all fair game.

## Licensing

This repository is **[Apache-2.0](LICENSE)**. You may use, copy, modify, distribute,
and commercialize it, including in closed-source and commercial products, subject to
the licence's attribution and notice terms. There is no separate permission to ask for.

It is part of Signetry's
[open-core model](https://github.com/Signetry/signetry/blob/main/LICENSING.md): the
integration surface (this repo and the other adapters) is Apache-2.0 so anyone can add
an agent, an editor, or a CI adapter, while the engine
([`Signetry/core`](https://github.com/Signetry/core)) is source-available under
BUSL-1.1 and converts to Apache-2.0 on 2030-08-31.

### The CLA still applies

Contributions are accepted under the [Contributor License Agreement](CLA.md), and the
CLA check gates every pull request. Open core is exactly why it is kept: code sometimes
moves across the line, and the CLA is what lets that happen without going back to every
past contributor. Note that it assigns copyright in a merged contribution to the
maintainer — see [LICENSING.md](https://github.com/Signetry/signetry/blob/main/LICENSING.md#contributions)
for what that does and does not mean. It does not take your Apache-2.0 rights away.

## What this repo is

The App itself is a **thin comment surface**. It carries no policy logic: every verdict
comes from `signetry-core`, and the comment never claims more than the signed receipt
does. A change that would let the App decide something on its own is out of scope — put
it in the engine instead.

Two properties must survive any change here:

- **Comment-only.** The App never merges, never approves, and never gates a PR.
- **The comment restates the receipt.** If the receipt says a gate is `unproven`, the
comment says `unproven` — never "passed".

## Signing the CLA (required before merge)

Expand All @@ -13,13 +49,16 @@ I have read the CLA Document and I hereby sign the CLA
```

Your acceptance is recorded in `signatures/cla.json`. A PR **cannot be merged** until
the CLA is signed. Signetry is **not open source** (All Rights Reserved) — by signing
you assign copyright/ownership of your contribution to the Owner and gain no right to
use, sell, or commercialize it yourself.
the CLA is signed.

## Credit

Contributors are **acknowledged** in [CONTRIBUTORS.md](CONTRIBUTORS.md), the Git
history, and release notes. This is attribution only — you may truthfully say you
contributed, but it grants no ownership and no right to use, sell, or rebrand the
project as your own. See the "Recognition of Contributors" clause in [CLA.md](CLA.md).
history, and release notes. Attribution is separate from trademark: you may freely say
you contributed, but please don't use the Signetry name to endorse or promote your own
product. See the "Recognition of Contributors" clause in [CLA.md](CLA.md).

## Conduct and security

By participating you agree to the [Code of Conduct](CODE_OF_CONDUCT.md). Please report
vulnerabilities privately — see [SECURITY.md](SECURITY.md).
Loading