Skip to content

Commit 858d201

Browse files
committed
added CODE_OF_CONDUCT.md, CONTRIBUTING.md, PULL_REQUEST_TEMPLATE.md, SECURITY.md
1 parent 77087b6 commit 858d201

4 files changed

Lines changed: 232 additions & 0 deletions

File tree

‎.github/PULL_REQUEST_TEMPLATE.md‎

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
## Summary
2+
3+
Describe the change in 1-3 sentences.
4+
5+
## Why this change?
6+
7+
Explain the problem this PR solves.
8+
9+
## What changed?
10+
11+
-
12+
-
13+
-
14+
15+
## Testing
16+
17+
Describe how this was tested.
18+
19+
## Documentation
20+
21+
- [ ] Documentation updated if needed
22+
- [ ] Screenshots added if UI/admin flow changed
23+
24+
## Notes
25+
26+
Anything reviewers should pay attention to.

‎CODE_OF_CONDUCT.md‎

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
# Code of Conduct
2+
3+
## Our standard
4+
5+
We want this project to be welcoming, constructive, and respectful.
6+
7+
Examples of positive behavior include:
8+
9+
- being respectful in discussions
10+
- giving actionable and specific feedback
11+
- assuming good intent
12+
- focusing on the project and the technical topic
13+
- being open to different ideas and levels of experience
14+
15+
Examples of unacceptable behavior include:
16+
17+
- harassment or personal attacks
18+
- insulting or dismissive language
19+
- hostile, discriminatory, or abusive behavior
20+
- deliberate disruption of discussions or reviews
21+
- publishing private information without permission
22+
23+
## Enforcement
24+
25+
Project maintainers may remove, edit, or reject comments, issues, pull requests, or other contributions that violate these standards.
26+
27+
## Reporting
28+
29+
If you experience or witness unacceptable behavior, contact the maintainer:
30+
31+
- Telegram: [@ilyarolf_dev](https://t.me/ilyarolf_dev)
32+
33+
## Scope
34+
35+
This Code of Conduct applies to issues, pull requests, discussions, and other community spaces related to this repository.

‎CONTRIBUTING.md‎

Lines changed: 113 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,113 @@
1+
# Contributing to AiogramShopBot
2+
3+
Thank you for your interest in contributing to AiogramShopBot.
4+
5+
This document explains how to propose changes, report bugs, and submit pull requests in a way that is easy to review and maintain.
6+
7+
## Ways to contribute
8+
9+
You can help by:
10+
11+
- reporting bugs
12+
- improving documentation
13+
- fixing typos and broken links
14+
- proposing new features
15+
- submitting code improvements
16+
- improving tests, deployment, and developer experience
17+
18+
## Before you start
19+
20+
Please:
21+
22+
1. Search existing issues and pull requests first.
23+
2. Open an issue before starting large changes.
24+
3. Keep changes focused and easy to review.
25+
26+
For small fixes such as typos, wording, or broken links, you can usually open a pull request directly.
27+
28+
## Reporting bugs
29+
30+
When reporting a bug, include as much useful context as possible:
31+
32+
- what you expected to happen
33+
- what actually happened
34+
- steps to reproduce the issue
35+
- logs or error messages
36+
- environment details
37+
- Python version
38+
- OS
39+
- database type and version
40+
- Redis version
41+
- deployment method (local, Docker, VPS)
42+
43+
## Suggesting features
44+
45+
When suggesting a feature, please describe:
46+
47+
- the problem you are trying to solve
48+
- why the feature is useful
49+
- a possible implementation idea
50+
- whether it affects users, admins, deployment, or integrations
51+
52+
## Pull request guidelines
53+
54+
Please follow these rules when opening a pull request:
55+
56+
- keep PRs small and focused
57+
- update documentation when behavior changes
58+
- avoid unrelated refactors in the same PR
59+
- use clear commit messages
60+
- explain the purpose of the change in the PR description
61+
62+
A good pull request usually includes:
63+
64+
- a short summary
65+
- the motivation for the change
66+
- screenshots or logs if relevant
67+
- notes about backward compatibility
68+
69+
## Code style
70+
71+
General expectations:
72+
73+
- prefer readable and explicit code
74+
- keep functions focused and maintainable
75+
- avoid unnecessary complexity
76+
- preserve existing project structure unless refactoring is justified
77+
78+
If you introduce a new dependency, explain why it is needed.
79+
80+
## Documentation changes
81+
82+
Documentation improvements are very welcome.
83+
84+
If you change:
85+
86+
- setup flow
87+
- environment variables
88+
- admin behavior
89+
- user-facing flows
90+
- referral or payment logic
91+
92+
please update the related documentation as part of the same pull request.
93+
94+
## Security-related changes
95+
96+
Do not open a public issue for sensitive vulnerabilities.
97+
98+
Please follow the instructions in [SECURITY.md](SECURITY.md).
99+
100+
## Review process
101+
102+
Maintainers may request:
103+
104+
- code changes
105+
- documentation updates
106+
- a smaller scope
107+
- clarification about architecture decisions
108+
109+
Not every contribution can be merged, but thoughtful contributions are appreciated.
110+
111+
## License
112+
113+
By contributing to this repository, you agree that your contributions will be licensed under the same license as the project.

‎SECURITY.md‎

Lines changed: 58 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,58 @@
1+
# Security Policy
2+
3+
## Supported versions
4+
5+
Security support is provided on a best-effort basis for the most actively maintained code in the default branch.
6+
7+
If versioned releases are introduced later, this table can be updated.
8+
9+
| Version | Supported |
10+
|-------------------------|-----------|
11+
| Default branch | ✅ |
12+
| Older snapshots / forks | ❌ |
13+
14+
## Reporting a vulnerability
15+
16+
Please do **not** open a public GitHub issue for security vulnerabilities.
17+
18+
Instead, report vulnerabilities privately through one of the following channels:
19+
20+
- Telegram: [@ilyarolf_dev](https://t.me/ilyarolf_dev)
21+
22+
When possible, include:
23+
24+
- a short description of the issue
25+
- affected component or feature
26+
- steps to reproduce
27+
- proof of concept if available
28+
- impact assessment
29+
- any suggested fix or mitigation
30+
31+
## What to expect
32+
33+
After a private report is received, the maintainer will try to:
34+
35+
1. confirm the issue
36+
2. assess the severity and impact
37+
3. prepare a fix or mitigation
38+
4. publish the patch when appropriate
39+
40+
Response and remediation times are best-effort and may vary depending on the complexity of the issue.
41+
42+
## Scope
43+
44+
Examples of security-relevant areas may include:
45+
46+
- authentication and admin access
47+
- webhook validation
48+
- JWT handling
49+
- SQLAdmin access control
50+
- payment logic and forwarding logic
51+
- secrets and environment variable handling
52+
- deployment and reverse proxy misconfiguration
53+
54+
## Disclosure policy
55+
56+
Please allow reasonable time for the vulnerability to be reviewed and fixed before public disclosure.
57+
58+
Responsible disclosure helps protect users and deployments of the project.

0 commit comments

Comments
 (0)