Skip to content

Contributing and Security

Fabrizio Degni edited this page Aug 25, 2026 · 2 revisions

Contributing and Security

Contributing

PALO welcomes focused contributions that improve operational AI governance, documentation, accessibility, translations, schemas, examples, interoperability, and evidence quality.

  1. Read the contribution guide.
  2. Check existing issues and pull requests.
  3. Fork the repository and create a focused branch.
  4. Add or update tests and documentation when relevant.
  5. Validate accessibility, responsive behavior, source files, and deterministic publication output.
  6. Open a pull request with the problem, scope, user impact, validation, and known limitations.

All participants must follow the Code of Conduct.

Security reporting

Do not open a public issue for a suspected vulnerability.

Read the Security Policy and report security concerns privately to security@paloframework.org with a description, reproduction steps, potential impact, and any suggested remediation.

Do not test PALO previews against systems, accounts, data, or tools that you do not own or have explicit authorization to assess.

Developer-preview expectations

The PALO-AI v2.7 runtime, Governance Hub, remote transports, approval flows, evidence and disclosure chains, data-assurance contracts, governed-execution adapters, and n8n/Dify/Microsoft AGT examples are reference implementations for isolated evaluation.

They do not replace production controls for principal identity, RBAC/ABAC, separation of duties, KMS/HSM custody, tenant isolation, signed policy promotion, service identity, high availability, backup and recovery, external evidence anchoring, incident operations, legal review, penetration testing, or cryptographic assessment.

Clone this wiki locally