Thanks for helping build GhostDeps. This project treats outside contributors as first-class from day one, so this document is written for you, not as an afterthought.
- Every change goes through a pull request. No direct pushes to
main. - Small, focused PRs. One concern per PR. If a change is getting big, split it.
- Link an issue. Every PR references the issue it closes (
Closes #123). - Tests travel with code. New behaviour lands with tests in the same PR.
- Docs travel with code. If you change behaviour, update the relevant doc in
docs/in the same PR. - Green CI or it doesn't merge. All checks must pass.
The merge gate keeps main green and every merge verdict auditable.
- Approval names the head. A pull request merges only after a reviewer posts an APPROVE comment naming the current head SHA. Any new push resets the verdict.
- Green at the approved head. All CI checks must pass at that exact SHA and GitHub must report the PR mergeable. Any push after approval, including a manual rebase, resets the verdict.
- Rebase-merge. Rebase-merge so
mainkeeps every granular commit. The replayed commits land as new SHAs, so the post-merge gate below is the integration check on what actually landed. - Post-merge gate: latest containing green. Main CI is the integration check. When a merge's own CI run is cancelled by concurrency supersession, the latest containing main commit going green is sufficient as the post-merge gate - no exact-SHA rerun - under three conditions: (a) containment: the green run's commit descends from the cancelled run's merge SHA; (b) same matrix: the containing run executes the same full job set, so a lint/typecheck-only run never counts; (c) red reopens: if the containing run fails, rerun the intermediate SHA to bisect which merge introduced the failure. Green closes; red bisects. Cancellation by supersession is a CI scheduling artifact, not a signal.
- Board hygiene on merge. Close the linked issue and move its card to Done.
Requires Node.js 22+ and pnpm (via corepack enable).
git clone https://github.com/rowkavdev/ghostdeps.git
cd ghostdeps
pnpm install
pnpm test
pnpm lint
pnpm typecheckGhostDeps is a pnpm monorepo:
packages/
core/ shared types, dependency model, adapter interface, analysis engine
adapters/ one package per ecosystem (javascript-typescript, python, rust, go, ...)
cli/ the ghostdeps command-line interface
github-app/ the GitHub App (webhooks, checks, annotations)
fixtures/ representative test repositories used by the test suites
docs/ architecture docs, ADRs, guides
The same analysis engine powers the CLI and the GitHub App. There is no second implementation.
The project board is the source of truth. Issues in Ready are unblocked and scoped; comment on one to claim it before starting. If you spot missing work, open an issue with a goal and done-criteria rather than a vague title.
Consequential technical choices are recorded as ADRs in docs/adr/. If your PR changes or reverses a decision, update or supersede the ADR in the same PR.
New ecosystems are added as adapters implementing the contract in packages/core. Read docs/contributing-adapters.md before starting one. Every adapter must pass the shared adapter contract tests and ship fixtures.
- TypeScript, strict mode, ESM.
- Prettier formats, ESLint lints. Both run in CI; run
pnpm formatbefore pushing. - Descriptive commit messages: what changed and why, not "fix stuff".
See SECURITY.md. Never open a public issue for a vulnerability.