Back to realm

Contribution Notice

Guidelines, cryptographic standards, and RCCL 1.0 licensing covenants for realm and realm-api.

Published on September 2026 | RCCL 1.0 Compliant

01. Philosophy & Open Source Spirit

realm is built upon the pillars of craftsmanship, overkill engineering, and shared open-source commons. We welcome contributions of all forms: bug fixes, performance optimizations, architectural enhancements, accessibility audits, and documentation refinements.

To preserve high software quality and repository integrity, all contributions submitted to realm and realm-api are held to strict engineering, conventional commit, and cryptographic verification standards.

02. Licensing Agreement (RCCL 1.0)

By submitting a pull request, patch, or code contribution to any realm repository, you agree that your contribution is provided under the terms of the Realm Collectives Community License (RCCL) Version 1.0.

RCCL SECTION A SUMMARY:

1. A copy of the RCCL license must accompany any redistribution of the Work or Derivative Works.

2. All copyright, patent, trademark, and attribution notices from the original Source must be preserved.

3. The original author's rights must be respected in any form of distribution.

03. Git Standards & Commit Requirements

Every commit merged into our repositories must satisfy the following three conditions:

1. Conventional Commits Specification

Format: type(scope): succinct description. Permitted types: feat, fix, perf, chore, docs, refactor, test.

2. Developer Certificate of Origin (DCO Sign-Off)

Every commit must include a Signed-off-by trailer verifying your right to submit the patch. Use git commit -s.

3. Cryptographic Signature Verification

All commits must be cryptographically signed with an SSH or GPG key registered on your GitHub account (git commit -S).

04. Verification Gates & Testing

Before proposing changes, ensure all automated verification gates pass locally. We enforce zero vulnerabilities and strict schema linting:

>_GO BACKEND (realm-api)
# 1. Run all unit & integration tests
go test -v ./test/...
# 2. Run security & vulnerability audits
make check

Requires 0 gosec findings, 0 govulncheck issues, and clean buf lint.

>_FRONTEND (realm-reference)
# 1. Type-check TypeScript codebase
pnpm exec tsc --noEmit
# 2. Run Next.js linting
pnpm lint

Requires zero type errors, clean ESLint, and responsive accessibility.

05. Responsible Security Disclosure

Security is taken with utmost seriousness. If you discover a security vulnerability (such as an authentication bypass, Landlock sandbox escape, SSRF, or token forgery), do NOT open a public GitHub issue.

Please report vulnerabilities confidentially via the Contact Form or email directly to irvanma@gnuweeb.org. We will acknowledge receipt within 48 hours and work with you on coordinated disclosure.

06. Community Covenant

We are committed to providing a friendly, safe, and welcoming environment for all contributors. We expect all participants to communicate with empathy, accept constructive feedback gracefully, and focus on what is best for the collective engineering commons.

YOU'VE REACHED THE END, CUH.
YOU'VE REACHED THE END, CUH.