From c11df483556722cba2063d841c4d4958b634e364 Mon Sep 17 00:00:00 2001 From: songsong Date: Mon, 21 Sep 2026 20:40:58 +0800 Subject: [PATCH] chore: establish public repository standards --- .github/ISSUE_TEMPLATE/bug_report.yml | 16 ++++++++++++++++ .github/dependabot.yml | 6 ++++++ .github/pull_request_template.md | 10 ++++++++++ .github/workflows/ci.yml | 25 +++++++++++++++++++++++++ .github/workflows/codeql.yml | 23 +++++++++++++++++++++++ AGENTS.md | 8 ++++++++ CONTRIBUTING.md | 9 +++++++++ LICENSE | 21 +++++++++++++++++++++ MEMORY.md | 12 ++++++++++++ README.md | 9 +++++++++ SECURITY.md | 7 +++++++ package.json | 8 ++++---- tests/test-package-contract.mjs | 15 +++++++++++++++ 13 files changed, 165 insertions(+), 4 deletions(-) create mode 100644 .github/ISSUE_TEMPLATE/bug_report.yml create mode 100644 .github/dependabot.yml create mode 100644 .github/pull_request_template.md create mode 100644 .github/workflows/ci.yml create mode 100644 .github/workflows/codeql.yml create mode 100644 AGENTS.md create mode 100644 CONTRIBUTING.md create mode 100644 LICENSE create mode 100644 MEMORY.md create mode 100644 SECURITY.md create mode 100644 tests/test-package-contract.mjs diff --git a/.github/ISSUE_TEMPLATE/bug_report.yml b/.github/ISSUE_TEMPLATE/bug_report.yml new file mode 100644 index 0000000..ec4528e --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.yml @@ -0,0 +1,16 @@ +name: Bug report +description: Report a reproducible plugin issue. +labels: [bug] +body: + - type: textarea + attributes: + label: What happened? + description: Remove API keys, tokens, and private URLs. + validations: + required: true + - type: textarea + attributes: + label: Reproduction + placeholder: DSH version, plugin version, provider route, and steps + validations: + required: true diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..ca79ca5 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,6 @@ +version: 2 +updates: + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md new file mode 100644 index 0000000..58b4699 --- /dev/null +++ b/.github/pull_request_template.md @@ -0,0 +1,10 @@ +## Summary + +Describe the user-visible effect and compatibility impact. + +## Verification + +- [ ] `npm test` +- [ ] `npm pack --dry-run` +- [ ] No credentials or private endpoint data included +- [ ] Upstream MIT attribution remains intact diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..3b86b21 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,25 @@ +name: CI + +on: + push: + branches: [main] + pull_request: + branches: [main] + +permissions: + contents: read + +jobs: + test: + runs-on: ubuntu-latest + strategy: + matrix: + node: [20, 22] + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: ${{ matrix.node }} + - run: npm test + - run: npm pack --dry-run + - run: git diff --check diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000..78730c9 --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,23 @@ +name: CodeQL + +on: + push: + branches: [main] + pull_request: + branches: [main] + schedule: + - cron: '23 4 * * 1' + +permissions: + contents: read + security-events: write + +jobs: + analyze: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - uses: github/codeql-action/init@v3 + with: + languages: javascript-typescript + - uses: github/codeql-action/analyze@v3 diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..ed98089 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,8 @@ +# Repository guidance + +Run `npm test` and `npm pack --dry-run` for code changes. Keep this plugin +host-only: it must not register a global DSH Settings page. Preserve the MIT +license, the `nobu121` author attribution, and the upstream remote. + +Use Conventional Commits. Never commit tokens, request payloads, or personal +paths. Record durable project decisions only in the root `MEMORY.md`. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..73eef53 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,9 @@ +# Contributing + +Open an issue before proposing a substantial behavior change. For a pull +request, keep the change focused, add or update a regression test, and run +`npm test` plus `npm pack --dry-run` locally. + +Do not add credentials, request payloads, or private endpoint URLs to source, +fixtures, issues, or pull requests. Changes must preserve the upstream MIT +license and author attribution. diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..b730e3d --- /dev/null +++ b/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2026 nobu121 + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/MEMORY.md b/MEMORY.md new file mode 100644 index 0000000..20ac6f5 --- /dev/null +++ b/MEMORY.md @@ -0,0 +1,12 @@ +# Project memory + +## Usage rules + +This is the only project memory file. Do not create tool-specific or hidden +memory directories. Add concise, durable decisions after a completed change. + +## 2026-09-21 + +- The public `songoao25/dsh-opencode-session` repository is an MIT-preserving + fork of `nobu121/dsh-opencode-session`; keep `upstream` configured. +- The plugin is host-only and intentionally has no global DSH Settings page. diff --git a/README.md b/README.md index 9604ab6..dab6dc9 100644 --- a/README.md +++ b/README.md @@ -5,6 +5,10 @@ plugin that automatically sends the **`x-opencode-session`** request header on model calls routed to **OpenCode / OpenCode Go** providers — one stable session id per DSH conversation. +This repository is a maintained public fork of +[nobu121/dsh-opencode-session](https://github.com/nobu121/dsh-opencode-session). +It preserves the upstream MIT license, author attribution, and Git history. + ## Why Since 2026-09-05 OpenCode's relay requires an `x-opencode-session` header on @@ -51,6 +55,11 @@ If you run DSH from a source checkout instead, load it as an overlay: ## Configuration +There is deliberately no global DSH Settings page. Enable or disable the +plugin from **Plugins → Installed → opencode-session**. The repair is +transparent at its defaults; its advanced host-side options stay in the +profile patch below so no unrelated global settings surface is added. + The plugin row lives in the bundle's `cordis.patch.yml`; all keys are optional: ```yaml diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..8f12420 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,7 @@ +# Security policy + +Please do not disclose security-sensitive reports in a public issue. Use the +repository's private security-advisory reporting flow and include the affected +version, a minimal reproduction, and any relevant logs with secrets removed. + +Supported versions are the latest commit on `main` and the latest npm release. diff --git a/package.json b/package.json index e698d6d..ee7216e 100644 --- a/package.json +++ b/package.json @@ -16,7 +16,7 @@ "node": ">=20" }, "scripts": { - "test": "node tests/test.mjs", + "test": "node tests/test.mjs && node tests/test-package-contract.mjs", "prepublishOnly": "npm test" }, "keywords": [ @@ -39,11 +39,11 @@ }, "repository": { "type": "git", - "url": "https://github.com/nobu121/dsh-opencode-session.git" + "url": "https://github.com/songoao25/dsh-opencode-session.git" }, - "homepage": "https://github.com/nobu121/dsh-opencode-session", + "homepage": "https://github.com/songoao25/dsh-opencode-session", "bugs": { - "url": "https://github.com/nobu121/dsh-opencode-session/issues" + "url": "https://github.com/songoao25/dsh-opencode-session/issues" }, "dsh": { "bundle": { diff --git a/tests/test-package-contract.mjs b/tests/test-package-contract.mjs new file mode 100644 index 0000000..54122d4 --- /dev/null +++ b/tests/test-package-contract.mjs @@ -0,0 +1,15 @@ +import assert from 'node:assert/strict' +import { existsSync, readFileSync } from 'node:fs' + +const pkg = JSON.parse(readFileSync(new URL('../package.json', import.meta.url), 'utf8')) +const patch = readFileSync(new URL('../cordis.patch.yml', import.meta.url), 'utf8') + +assert.equal(pkg.name, 'dsh-opencode-session') +assert.equal(pkg.license, 'MIT') +assert.equal(pkg.author?.name, 'nobu121', 'keep the upstream author attribution') +assert.match(pkg.repository.url, /songoao25\/dsh-opencode-session/) +assert.ok(existsSync(new URL('../LICENSE', import.meta.url))) +assert.ok(existsSync(new URL('../SECURITY.md', import.meta.url))) +assert.match(patch, /name: dsh-opencode-session/) +assert.match(patch, /id: opencode-go-session-header/) +console.log('package contract OK')