add
添加项目文件
This commit is contained in:
39
zh/CONTRIBUTING.md
Normal file
39
zh/CONTRIBUTING.md
Normal file
@@ -0,0 +1,39 @@
|
||||
# Contributing
|
||||
|
||||
When contributing, please discuss the change you wish to make via issue
|
||||
with the owners of this repository before making a change.
|
||||
|
||||
Please note we have a code of conduct, please follow it in all your interactions with the project.
|
||||
|
||||
## Pull Request Process
|
||||
|
||||
1. Make sure that all build or compilation dependencies are removed when performing a build.
|
||||
2. Update the README.md with details of changes to the interface, this includes new environment
|
||||
variables, exposed ports, useful file locations and container parameters.
|
||||
3. Increase the version numbers in any examples files and the README.md to the new version that this
|
||||
Pull Request would represent. The versioning scheme we use is [SemVer](http://semver.org/).
|
||||
4. You may merge the Pull Request in once you have the sign-off of two other developers, or if you
|
||||
do not have permission to do that, you may request the second reviewer to merge it for you.
|
||||
|
||||
|
||||
### Collaborate on fixes for security vulnerabilities in private forks
|
||||
|
||||
Working in the open means that it is impossible to hide things. And yet, sometimes you will want
|
||||
to work on some changes to the code in private, for example when fixing a security vulnerability.
|
||||
|
||||
Working on a fix in the open might allow attackers to reverse engineer the bug and attack our users.
|
||||
Since GitHub provides a mechanism to easily create a private fork of our repo, please use these
|
||||
private forks to collaborate on a security fix.
|
||||
|
||||
### Publish maintainer advisories for security fixes
|
||||
|
||||
Fixing a security vulnerability is no small feat and we should tell our users about it.
|
||||
We will do it in a way that will make it easy for you to learn about it and patch
|
||||
|
||||
Since GitHub provides an easy way to publish a security advisory, this will
|
||||
be incorporated and you could add it into your security scanning tools, the ones you
|
||||
depend on to keep your applications secure.
|
||||
|
||||
## Read More
|
||||
|
||||
[Leverage Open Source Modules management](https://leverage.binbash.com.ar/how-it-works/infra-as-code-library/infra-as-code-library-forks/)
|
||||
Reference in New Issue
Block a user