git clone https://github.com/hyperpolymath/echidna.git
cd echidna
# Using mise (recommended: provision the pinned toolchain)
mise install
# Task runner (see Justfile)
just --list # available tasks
just check # verify setup / static checks
just test # run the test suiteBefore reporting:
- Search existing issues
- Check if it's already fixed in
main - Determine which perimeter the bug affects
When reporting:
Use the bug report template and include:
- Clear, descriptive title
- Environment details (OS, versions, toolchain)
- Steps to reproduce
- Expected vs actual behaviour
- Logs, screenshots, or minimal reproduction
Before suggesting:
- Check the roadmap if available
- Search existing issues and discussions
- Consider which perimeter the feature belongs to
When suggesting:
Use the feature request template and include:
- Problem statement (what pain point does this solve?)
- Proposed solution
- Alternatives considered
- Which perimeter this affects
Look for issues labelled:
good first issue— Simple Perimeter 3 taskshelp wanted— Community help neededdocumentation— Docs improvementsperimeter-3— Community sandbox scope
docs/short-description # Documentation (P3)
test/what-added # Test additions (P3)
feat/short-description # New features (P2)
fix/issue-number-description # Bug fixes (P2)
refactor/what-changed # Code improvements (P2)
security/what-fixed # Security fixes (P1-2)
We follow Conventional Commits:
<type>(<scope>): <description>
[optional body]
[optional footer]
Every commit that reaches the default branch must be signed; a ruleset refuses unsigned pushes. Estate policy: SIGNING-POLICY.
- People and interactive agents sign with an SSH key registered on GitHub
as a signing key (
gpg.format=ssh,user.signingkey=<key>.pub,commit.gpgsign=true). The committer email must be verified on that account. - Apps, bots and workflows never
git pushlocal commits. They write through the API (createCommitOnBranchor the estatesigned-pushaction) so that GitHub signs each commit. - Merge PRs with squash. The ruleset checks every commit on the PR branch,
not just the result, so one unsigned commit blocks the merge. Re-create such a
branch with signed commits (
git cherry-pick -S) and open a new PR. Rebase-merge replays commits unsigned and is disabled.