Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
48 changes: 33 additions & 15 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -1,27 +1,45 @@
# Contributing
<div align="center">

Thanks for helping improve Command Center. Small fixes, documentation improvements, and focused feature proposals are welcome.
# 🤝 Contributing to Command Center

## Report a bug or propose a feature
Thanks for helping improve Command Center.<br />
Small fixes, documentation improvements, and focused feature proposals are welcome.

Check [existing issues](https://github.com/Commanderx-code/command-center/issues) first, then use the bug report or feature request template. For bugs, include the app version, distribution, installation method, steps to reproduce, and expected versus actual behavior. Mention whether the problem occurs in the desktop app or browser preview.
<sub>[🏠 README](README.md) &nbsp;·&nbsp; [📚 Docs](docs/README.md) &nbsp;·&nbsp; [🔐 Security](SECURITY.md) &nbsp;·&nbsp; [🐛 Issues](https://github.com/Commanderx-code/command-center/issues)</sub>

**Security vulnerabilities:** don't open a public issue. Report them privately as described in [SECURITY.md](SECURITY.md).
</div>

Remove secrets and personal information from screenshots and logs. Terminal transcripts and configuration files can contain credentials; include only the relevant, redacted excerpt.
## 🐛 Report a bug or propose a feature

## Work on a change
Check [existing issues](https://github.com/Commanderx-code/command-center/issues) first, then use the bug report or feature request template. For bugs, include:

1. Fork the repository and create a branch for your change.
2. Follow the [installation guide](docs/installation.md#from-source-on-archgaruda) to set up the development environment.
3. Keep the change focused and update documentation when behavior changes.
4. Run the relevant [development checks](docs/development.md#checks). For interface changes, include a screenshot and verify the desktop behavior when applicable.
5. Open a pull request explaining the problem, resulting behavior, and how you verified it.
- the app version, distribution, and installation method,
- steps to reproduce,
- expected versus actual behavior,
- whether the problem occurs in the desktop app or the browser preview.

For changes to installers or catalog scripts, start in [Commander Toolbox](https://github.com/Commanderx-code/commander-toolbox). Command Center consumes a pinned revision of its shared core.
> [!CAUTION]
> **Security vulnerabilities:** don't open a public issue. Report them privately as described in [SECURITY.md](SECURITY.md).

## Implementation expectations
> [!WARNING]
> Remove secrets and personal information from screenshots and logs. Terminal transcripts and configuration files can contain credentials; include only the relevant, redacted excerpt.

## 🛠️ Work on a change

1. 🍴 Fork the repository and create a branch for your change.
2. 📦 Follow the [installation guide](docs/installation.md#from-source-on-archgaruda) to set up the development environment.
3. 🎯 Keep the change focused and update documentation when behavior changes.
4. ✅ Run the relevant [development checks](docs/development.md#checks). For interface changes, include a screenshot and verify the desktop behavior when applicable.
5. 📬 Open a pull request explaining the problem, resulting behavior, and how you verified it.

> [!TIP]
> For changes to installers or catalog scripts, start in [Commander Toolbox](https://github.com/Commanderx-code/commander-toolbox). Command Center consumes a pinned revision of its shared core.

## 📐 Implementation expectations

Keep the frontend and Rust responsibilities consistent with the existing architecture. Preserve command review, compatibility checks, cancellation, private local storage, and configuration conflict detection when editing execution paths. Use temporary fixtures for tests that involve Git, backups, or subprocesses.

Prefer clear code and a small dependency footprint. Explain any new dependency or change to platform requirements in the pull request. Report checks you could not run rather than marking them as passed.
Prefer clear code and a small dependency footprint. Explain any new dependency or change to platform requirements in the pull request.

> [!IMPORTANT]
> Report checks you could not run rather than marking them as passed.
42 changes: 30 additions & 12 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,23 @@
# Security policy
<div align="center">

## Reporting a vulnerability
# 🔐 Security policy

Please report vulnerabilities privately through GitHub: **[Report a vulnerability](https://github.com/Commanderx-code/command-center/security/advisories/new)** (Security tab → *Report a vulnerability*). Don't open a public issue, discussion, or pull request for a security problem.
How to report a vulnerability in Command Center, and what counts as one.

<sub>[🏠 README](README.md) &nbsp;·&nbsp; [📚 Docs](docs/README.md) &nbsp;·&nbsp; [🤝 Contributing](CONTRIBUTING.md)</sub>

<br />

**[🛡️ Report a vulnerability privately](https://github.com/Commanderx-code/command-center/security/advisories/new)**

</div>

## 📨 Reporting a vulnerability

Please report vulnerabilities privately through GitHub: **[Report a vulnerability](https://github.com/Commanderx-code/command-center/security/advisories/new)** (Security tab → _Report a vulnerability_).

> [!CAUTION]
> Don't open a public issue, discussion, or pull request for a security problem.

Include what you can:

Expand All @@ -13,26 +28,29 @@ Include what you can:

You'll get a reply in the private advisory. Once a fix is ready, it ships in a patch release, and the advisory is published with credit to you unless you'd rather stay anonymous. Please keep the details private until then.

## Supported versions
## 🗓️ Supported versions

> [!IMPORTANT]
> Security fixes go into the latest release only. Update to the newest version before reporting, and check whether the problem still occurs.

Security fixes go into the latest release only. Update to the newest version before reporting, and check whether the problem still occurs.
| Version | Supported |
| -------------- | :-------: |
| 0.7.x (latest) | ✅ |
| Older | ❌ |

| Version | Supported |
|---|---|
| 0.7.x (latest) | ✅ |
| Older | ❌ |
## 🎯 Scope

## Scope
Command Center runs locally as your normal user, so the most important boundary is **untrusted data reaching the app**.

Command Center runs locally as your normal user, so the most important boundary is **untrusted data reaching the app**. Examples of in-scope problems:
✅ **In scope**, for example:

- a repository, submodule, Git remote, or its output making the app run commands or misbehave without your review;
- a setup bundle or settings import changing what runs automatically or reading files it shouldn't;
- credentials or private data leaking to other local users, logs, Activity, or exports;
- a way around command review, so something runs that you didn't approve;
- problems in the release packages, the Arch recipe, or the CI workflows that build them.

Out of scope:
❌ **Out of scope:**

- actions that need someone already running code as your user, or with root;
- commands you reviewed and approved yourself;
Expand Down
Loading