Skip to content

Commit 49e6bb1

Browse files
mattaerealElliotFriedmanengn33rRobert-MacWhapinalikefruit
authored
Updating main on missing commits due to previous selective-merging (security-alliance#192)
* Code review additions (security-alliance#145) * add pre-audit prep stage with links to solcurity and simple security toolkit Signed-off-by: Elliot <elliotfriedman3@gmail.com> * add prepare thoroughly section Signed-off-by: Elliot <elliotfriedman3@gmail.com> * prepare thoroughly -> come prepared Signed-off-by: Elliot <elliotfriedman3@gmail.com> --------- Signed-off-by: Elliot <elliotfriedman3@gmail.com> * Updated contributing and readme.md * Removed catpuccin, updated mdbook and admonish. (security-alliance#147) * Removed catpuccin, updated mdbook and admonish. * Removing deprecated themes from UI, and fixing admonish version on vercel_build * Testing admonish through vercel automated deployment * Updating wordlist.txt * Clean update of logo and favicon. (security-alliance#151) * Updating develop to the new and more humane beginning of a written Opsec Framework (security-alliance#154) * Updating Opsec first iteration after re-write, CorPrinciples checkpoint * Updating Opsec structure and initial approach for some of the new contents. * Updating human centered security * Stop tracking generated tagsindex.js file * Updating gitignore * Removing old readme that explained how tags work. * New structure * First iter of Fundamentals * First iter of Fundamentals * Restructuring Opsec once again. Re-wrtitten principles and threat modeling * Forgot attribution. * Added key takeaways and removed redundancy * Updating Risk management and removing overlap from Threat modeling * Fixing broken link * Spellcheck's wordlist update * Spellcheck's wordlist update * Spellcheck's wordlist update * Updating Opsec with latest updates (security-alliance#157) * Updating Opsec first iteration after re-write, CorPrinciples checkpoint * Updating Opsec structure and initial approach for some of the new contents. * Updating human centered security * Stop tracking generated tagsindex.js file * Updating gitignore * Removing old readme that explained how tags work. * New structure * First iter of Fundamentals * First iter of Fundamentals * Restructuring Opsec once again. Re-wrtitten principles and threat modeling * Forgot attribution. * Added key takeaways and removed redundancy * Updating Risk management and removing overlap from Threat modeling * Fixing broken link * Spellcheck's wordlist update * Spellcheck's wordlist update * Spellcheck's wordlist update * Updating with tincho's review * Fixing grammar issues and spellcheck * Updating wordlist.txt * Initial draft of personal security travel guide! (security-alliance#158) * Updating Opsec first iteration after re-write, CorPrinciples checkpoint * Updating Opsec structure and initial approach for some of the new contents. * Updating human centered security * Stop tracking generated tagsindex.js file * Updating gitignore * Removing old readme that explained how tags work. * New structure * First iter of Fundamentals * First iter of Fundamentals * Restructuring Opsec once again. Re-wrtitten principles and threat modeling * Forgot attribution. * Added key takeaways and removed redundancy * Updating Risk management and removing overlap from Threat modeling * Fixing broken link * Spellcheck's wordlist update * Spellcheck's wordlist update * Spellcheck's wordlist update * Updating with tincho's review * Fixing grammar issues and spellcheck * Updating wordlist.txt * Security travel guide from Notion * Attribution * Updating naming on opsec travel guide * Updating, and re-ordering paragraphs from opsec travel guide * Attribution to sources * Add Secure Multisig Signing Process (security-alliance#122) * Add secure multisig signing process * Add multisig best practices page, update msig signing process * Add additional best practices from EF doc * Add final comment for this PR * Removing the old operational-security folder, moving secure-multisig contents within wallet-security, and re-generated the overview of frameworks with AI. * Safe Harbor Docs (security-alliance#144) Co-authored-by: Matías Aereal Aeón <388605+mattaereal@users.noreply.github.com> * doc: instruction for re-writing history to sign commits (security-alliance#156) * Tidy plugins (security-alliance#143) * Tody Plugins Signed-off-by: Robert MacWha <trebor.ahwcam@gmail.com> * doc: fix robert's website --------- Signed-off-by: Robert MacWha <trebor.ahwcam@gmail.com> * feat: overhaul of the Wallet Security section (security-alliance#164) * docs: update README for new structure * docs: update documentation on custodial vs non-custodial and hot vs cold wallets * docs: add user security guides for beginners and intermediates * docs: add advanced security guides * docs: add key management * docs: add tools and resources * docs: add signing and verifation section * docs: improvements in AA and EIP7701 * docs: improves the entire section * docs: deletion of obsolete sections * docs: add new item hardwallet * docs: fixed typo * docs: Refine wallet security guides for accuracy and clarity * docs: Apply light content adjustments and add 'reviewed' tag. * archive Developer Key Management section for later * small format changes * docs: refactor updated navigation * docs: Update contribution and documentation configuration * feat: fix extra fields & add verbose errors (security-alliance#167) * feat: fix extra fields & add verbose errors * fix: switch back to book.for_each_mut Also cache all errors instead of just the first * feat: log error when deserializing contributors json * feat: fix UI differences * fix: re-add company attribution * fix: add alias for fact-checked * fix: jitter on hover contributors * fix: urls scrolling * fix: display:content * fix: `fact_checked` spelling * fix: throw error if role alias not found * tidy: role_aliases * Bump crossbeam-channel (security-alliance#166) Bumps the cargo group with 1 update in the /plugin/mdbook-metadata directory: [crossbeam-channel](https://github.com/crossbeam-rs/crossbeam). Updates `crossbeam-channel` from 0.5.14 to 0.5.15 - [Release notes](https://github.com/crossbeam-rs/crossbeam/releases) - [Changelog](https://github.com/crossbeam-rs/crossbeam/blob/master/CHANGELOG.md) - [Commits](crossbeam-rs/crossbeam@crossbeam-channel-0.5.14...crossbeam-channel-0.5.15) --- updated-dependencies: - dependency-name: crossbeam-channel dependency-version: 0.5.15 dependency-type: indirect dependency-group: cargo ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Fix several misc (security-alliance#168) * Added some things to gitignore, particularly to use claude. * Correcting attribution * Updating steward, and improving tags UI * Removing spell-check from develop. Only on main from now on. Exploratory. * feat: security testing - solidity focused (security-alliance#163) * feat: security testing - solidity focused * fix: lint * fix: josselins review * fix: reverse aderyn and slither order * fix: patrickalphac contributor after merge * Introducing Decentralized IR Framework (security-alliance#165) * added DeIRF framework * new de-irf framework * adjusted summary as requested --------- Co-authored-by: Ken Toler <ken.toler@gmail.com> * feat: external security reviews & patrick addition (security-alliance#160) * feat: external security reviews & patrick addition * fix: lint * fix: moved smart contract audits to their own section * Adding to the outline the latest pushed content. * Bump mdbook version (security-alliance#177) * Update vercel_build.sh * Update printed statement * feat: added more information on wallet security (security-alliance#173) * feat: added more information on wallet security * fix: remove named solutions * Update PULL_REQUEST_TEMPLATE.md (security-alliance#174) * fix: stewards (security-alliance#172) * Update tldr.md (security-alliance#181) Added a line to "While Traveling" * Update README.md (security-alliance#178) I improved clarity in OpSec overview with simplified explanation and added detail on goal * Update implementation-process.md (security-alliance#179) Fixed punctuation to make the text clearer, added colons, commas, and cleaned up brackets. * feat: updating linting, devcontainer, and local development (security-alliance#184) * feat: updating linting, devcontainer, and local development * Update justfile --------- Co-authored-by: Matías Aereal Aeón <388605+mattaereal@users.noreply.github.com> * Going back to 0.4.40 stable. * Fix spelling issues and update wordlist (security-alliance#188) - Fixed 'asume' -> 'assume' in src/opsec/travel/guide.md - Fixed 'cybercrmiminals' -> 'cybercriminals' in src/opsec/travel/guide.md - Added 78 legitimate technical terms, brand names, and valid words to wordlist.txt - Includes terms like Counterparty, Invariants, Utils, and many others - Cleaned up wordlist formatting and removed invalid entries * Fix typos in mdbook-metadata README.md and add renderer to wordlist - Fix 'pagse' to 'pages' - Fix 'requrie' to 'require' - Fix 'seperate' to 'separate' - Add 'renderer' to wordlist.txt * Update threat-modeling-overview.md (security-alliance#182) * Clarified 'Team changes' to include onboarding and offboarding key personnel * Added structured 'Further Reading & Tools' section with grouped references and tools * Updating Safe Harbor Documentation (security-alliance#186) * Enhance Safe Harbor documentation and contributor list - Updated SUMMARY.md to include new resources for Safe Harbor, such as self-checklists and adoption guides. - Removed outdated key terms and protocol documentation from the Safe Harbor section. - Expanded the README.md to provide clearer explanations of Safe Harbor's purpose, adoption process, and benefits, including new visuals and testimonials from industry leaders. - Added Dickson Wu as a contributor in contributors.json with relevant details. * Update Safe Harbor documentation links for consistency - Changed links in various templates and guides to point to local markdown files instead of external Notion pages for better accessibility. - Updated the adoption details in the DAO proposal and non-DAO scope templates to reflect the new link structure. - Revised the self-adoption guide and checklist to ensure all references are consistent with the new documentation format. * Update Safe Harbor section in SUMMARY.md with new resources - Added links to new documentation including self-checklist, self-adoption guide, scope terms, on-chain adoption guide, DAO proposal template, and non-DAO scope template. - Removed outdated protocol and key terms links for improved clarity and organization. * Refactor Safe Harbor documentation for clarity and consistency - Updated the Safe Harbor eligibility checklist title and content for improved clarity. - Added new tags to various templates to enhance categorization. - Revised contact information in multiple documents to use a unified email format. - Ensured all references to Safe Harbor align with the latest documentation standards. * Update src/config/contributors.json Co-authored-by: Robert MacWha <trebor.ahwcam@gmail.com> * Remove integration mapping documentation file * Update src/safe-harbor/README.md Co-authored-by: Robert MacWha <trebor.ahwcam@gmail.com> * Update src/safe-harbor/scope-terms.md Co-authored-by: Robert MacWha <trebor.ahwcam@gmail.com> * Update src/safe-harbor/self-checklist.md Co-authored-by: Robert MacWha <trebor.ahwcam@gmail.com> * Update src/safe-harbor/on-chain-adoption-guide.md Co-authored-by: Robert MacWha <trebor.ahwcam@gmail.com> * Update src/safe-harbor/README.md Co-authored-by: Robert MacWha <trebor.ahwcam@gmail.com> * Update src/safe-harbor/scope-terms.md Co-authored-by: Robert MacWha <trebor.ahwcam@gmail.com> * Remove DAO Proposal and Non-DAO Scope Templates from Safe Harbor documentation - Deleted the DAO Proposal Template and Non-DAO Scope Template files to streamline the Safe Harbor resources. - Updated SUMMARY.md and config/SUMMARY.md.develop to reflect the removal of these templates, enhancing clarity and organization. * Refactor Safe Harbor documentation for clarity and consistency - Removed unnecessary horizontal lines from multiple sections in the on-chain adoption guide, scope terms, self-adoption guide, and self-checklist to improve readability. - Enhanced the overall structure of the documents by streamlining formatting. --------- Co-authored-by: Robert MacWha <trebor.ahwcam@gmail.com> * Updating outlines. Removing empty frameworks from main * Fixing broken link in PR template * Fixing grammar issues and spellcheck --------- Signed-off-by: Elliot <elliotfriedman3@gmail.com> Signed-off-by: Robert MacWha <trebor.ahwcam@gmail.com> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Elliot <34463580+ElliotFriedman@users.noreply.github.com> Co-authored-by: engn33r <engn33r@users.noreply.github.com> Co-authored-by: Robert MacWha <trebor.ahwcam@gmail.com> Co-authored-by: Piña <32434364+pinalikefruit@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Patrick Collins <54278053+PatrickAlphaC@users.noreply.github.com> Co-authored-by: relotnek <kentoler@gmail.com> Co-authored-by: Ken Toler <ken.toler@gmail.com> Co-authored-by: David <100804766+davidthegardens@users.noreply.github.com> Co-authored-by: NFTDreww <158506653+NFTDreww@users.noreply.github.com> Co-authored-by: Godwin Udo <102424075+GodwinDA@users.noreply.github.com> Co-authored-by: Yasir <100064629+damboy0@users.noreply.github.com> Co-authored-by: Dickson Wu <33645481+DicksonWu654@users.noreply.github.com>
1 parent f491dd6 commit 49e6bb1

140 files changed

Lines changed: 6117 additions & 2118 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.devcontainer/Dockerfile

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
# Base debian build with VS Code devcontainer base
2+
FROM mcr.microsoft.com/vscode/devcontainers/base:debian
3+
4+
# Update packages and install only essential dependencies
5+
RUN apt-get update && apt-get install -y \
6+
build-essential \
7+
pkg-config \
8+
libssl-dev \
9+
aspell \
10+
aspell-en \
11+
&& apt-get clean \
12+
&& rm -rf /var/lib/apt/lists/*
13+
14+
# Switch to vscode user
15+
USER vscode
16+
17+
# Install Rust and Cargo for vscode user
18+
RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
19+
ENV PATH="/home/vscode/.cargo/bin:${PATH}"
20+
21+
# Install mdBook and mdbook-admonish
22+
RUN /home/vscode/.cargo/bin/cargo install mdbook mdbook-admonish
23+
24+
# Install just command runner
25+
RUN /home/vscode/.cargo/bin/cargo install just
26+
27+
# Copy markdownlint-cli2 from its Docker image (need root for this)
28+
USER root
29+
COPY --from=davidanson/markdownlint-cli2:latest /usr/local/bin/markdownlint-cli2 /usr/local/bin/markdownlint-cli2
30+
RUN chmod +x /usr/local/bin/markdownlint-cli2
31+
32+
# Switch back to vscode user
33+
USER vscode
34+
35+
# Set working directory
36+
WORKDIR /workspace
37+
38+
# Ensure cargo is in PATH for vscode user
39+
RUN echo 'export PATH="/home/vscode/.cargo/bin:$PATH"' >> /home/vscode/.bashrc

.devcontainer/devcontainer.json

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
{
2+
"name": "Security Frameworks DevContainer",
3+
"build": {
4+
"dockerfile": "Dockerfile"
5+
},
6+
"features": {},
7+
"customizations": {
8+
"vscode": {
9+
"extensions": [
10+
"yzhang.markdown-all-in-one",
11+
"rust-lang.rust-analyzer",
12+
"tamasfe.even-better-toml"
13+
],
14+
"settings": {
15+
"terminal.integrated.defaultProfile.linux": "bash",
16+
"terminal.integrated.profiles.linux": {
17+
"bash": {
18+
"path": "/bin/bash"
19+
}
20+
}
21+
}
22+
}
23+
},
24+
"forwardPorts": [
25+
3000
26+
],
27+
"workspaceMount": "source=${localWorkspaceFolder},target=/workspace,type=bind,consistency=cached",
28+
"workspaceFolder": "/workspace",
29+
"postCreateCommand": "echo 'DevContainer ready! Run \"just serve\" to start the mdBook server.'"
30+
}

.github/PULL_REQUEST_TEMPLATE.md

Lines changed: 8 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,26 +1,18 @@
11
## Frameworks PR Checklist
22

3-
Thank you for contributing to the Security Frameworks! Before you open a PR, make sure to read [information for contributors](https://framework.securityalliance.org/book/contribute/contribute.html) and take a look at the following checklist:
3+
Thank you for contributing to the Security Frameworks! Before you open a PR, make sure to read [information for contributors](https://frameworks.securityalliance.dev/contribute/contributing.html) and take a look at the following checklist:
44

55
- [ ] Describe your changes, substitute this text with the information
6-
- [ ] If you are touching an existing piece of content, ask the original creator for review
7-
- [ ] If you need feedback for your content from wider community, share the PR in our Discord
6+
- [ ] If you are touching an existing piece of content, tag current contributors from the attribution list
7+
- [ ] If there is a steward for that framework, ask the steward to review it
8+
- [ ] If you're modifying the general outline, make sure to use `src/config/SUMMARY.develop` and not `src/SUMMARY.md`
9+
- [ ] If you need feedback for your content from the wider community, share the PR in our Discord
810
- [ ] Review changes to ensure there are no typos, see instructions below
911

1012
<!--
1113
ℹ️ Checking for typos locally
1214
1. Install [aspell](https://www.gnu.org/software/aspell/) for your platform.
13-
2. Navigate to the project root and run:
14-
```
15-
for f in **/*.md ; do echo $f ; aspell --lang=en_US --mode=markdown --home-dir=. --personal=wordlist.txt --ignore-case=true --camel-case list < $f | sort | uniq -c ; done
16-
```
17-
18-
ℹ️ Fixing typos
19-
1. Fix typos: Open the relevant files and fix any identified typos.
20-
2. Update wordlist: If a flagged word is actually a project-specific term add it to `wordlist.txt` in the project root.
21-
Each word should be listed on a separate line.
22-
* 🚧 Remember:
23-
* When adding new words it must NOT have any spaces or special characters within or around it.
24-
* \`wordlist\` is NOT case sensitive.
25-
* Use backticks to quote code variables so as to not bloat the \`wordlist\`.
15+
2. Install [markdownlint-cli2](https://github.com/DavidAnson/markdownlint-cli2)
16+
3. Install [just](https://github.com/casey/just)
17+
4. Run `just lint`
2618
-->

.github/workflows/md-lint.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ jobs:
1010
runs-on: ubuntu-latest
1111
steps:
1212
- uses: actions/checkout@v4
13-
- uses: DavidAnson/markdownlint-cli2-action@v15
13+
- uses: DavidAnson/markdownlint-cli2-action@v20
1414
continue-on-error: true
1515
with:
1616
globs: |

.github/workflows/spell-check.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,6 @@ on:
44
pull_request:
55
branches:
66
- main
7-
- develop
8-
97
jobs:
108
typo_check:
119
name: 🥢 Spell check

.gitignore

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,3 +19,15 @@ Cargo.lock
1919
# Ignore contributors index file to prevent watch loops
2020
theme/contributors/contributorsindex.js
2121
theme/tags/tagsindex.js
22+
23+
# Ignore claude-code installation
24+
claude-code
25+
@anthropic-ai/claude-code
26+
27+
# Node.js dependencies
28+
node_modules/
29+
package.json
30+
package-lock.json
31+
32+
# Claude Code configuration
33+
CLAUDE.md

README.md

Lines changed: 72 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -1,28 +1,54 @@
11
# Security Frameworks content repository
22

3-
Official repository to the Security Frameworks by SEAL. This repository contains the entire
4-
structure and contents of the frameworks. Feel free to suggest from new categories to grammar
5-
corrections. Collaboration is open to everyone. **This is a work in progress.**
3+
Official repository to the Security Frameworks by SEAL. This repository contains the entire structure and contents of the frameworks. Feel free to suggest from new categories to grammar corrections. Collaboration is open to everyone. **This is a work in progress.**
64

7-
If you want to know more about the frameworks or take a peek at the live book go to the following
8-
branches below: [Main](https://seal-frameworks.vercel.app/),
9-
[Development](https://frameworks-git-develop-seal-frameworks.vercel.app/?_vercel_share=zOI0Q3riUfDv1Lq1IylFz2hXQzYPcmLp).
5+
If you want to know more about the frameworks or take a peek at the live book go to the following branches: [Main](frameworks.securityalliance.org), [Development](frameworks.securityalliance.dev).
106

11-
Production will be at [frameworks.securityalliance.org](https://frameworks.securityalliance.org),
12-
but not yet available.
7+
# Prerequisites
8+
9+
- [Rust/cargo](https://www.rust-lang.org/tools/install) (For building/serving mdBook)
10+
- [markdownlint-cli2](https://github.com/DavidAnson/markdownlint-cli2) (For linting markdown files)
11+
- [GNU Aspell](https://sourceforge.net/projects/aspell/) (For spell checking)
12+
- [just](https://github.com/casey/just) (For running commands)
1313

1414
## Quick installation and local setup
1515

1616
1. `gh repo clone security-alliance/frameworks`
1717
2. `git checkout develop`
18-
3. `cargo install mdbook mdbook-admonish mdbook-catppuccin`
19-
4. `./serve.sh`
18+
3. `just serve`
2019

2120
## Collaboration
2221

23-
There are currently two ways to collaborate. The first one is by logging from your Vercel account
24-
and commenting directly on the deployed version of the book, and the second one is by forking the
25-
repository and creating a pull request.
22+
There are currently several ways to collaborate:
23+
24+
1. Using the "Suggest an edit" button on any page to make quick edits
25+
2. Contributing to a specific framework through its dedicated branch
26+
3. Forking the repository and creating a pull request to the develop branch
27+
4. Commenting directly on the deployed version
28+
29+
> ⚠️ Please sign and verify every commit. If you've accidentally created unsigned
30+
> commits in your history, you can resolve them by setting up [signature verification](https://docs.github.com/en/authentication/managing-commit-signature-verification/about-commit-signature-verification#gpg-commit-signature-verification)
31+
> on github and re-writing your history using the below commands.
32+
>
33+
> ```
34+
> git pull origin develop
35+
> git reset --soft develop
36+
> git commit -s -m "Commit Message"
37+
> git push --force
38+
> ```
39+
40+
### Framework-specific branches
41+
42+
Before contributing, check if there's a [Steward](https://frameworks.securityalliance.dev/contribute/contributors.html#stewards) for the specific framework you're interested in, and reach out. We usually have separate branches pre-develop for frameworks with stewards.
43+
44+
The naming convention is `fw_framework_name`, for example `fw_opsec`, `fw_community_mgmt`. Ideally, you'll fork these framework-specific branches, as they typically have more updated information than what's available in the develop branch.
45+
46+
After making your changes:
47+
1. Run the linting command `just lint`
48+
2. Submit a PR to the framework-specific branch and let the steward know
49+
3. After reviews, a PR can be submitted from the framework branch to the develop branch
50+
51+
If there's no specific branch created, that framework is still "headless," which means you can become its steward! See more in the [Stewards](src/contribute/stewards.md) section.
2652
2753
### Comments
2854
@@ -32,26 +58,38 @@ To comment on the live version of the book under development, you will need to l
3258
3359
1. Fork the repository. Click on the "Fork" button at the top right corner of the page.
3460
2. Clone the forked repository to your local machine. Open your terminal or command prompt.
35-
`git clone https://github.com/your-username/frameworks.git`
36-
3. Make sure you're in the develop branch first.
37-
`git checkout develop`
38-
4. Inside the folder create a new branch based on `develop`.
39-
`git checkout -b develop`
40-
5. Make your changes.
41-
6. Make sure your changes don't break anything by testing it in the local setup (see above).
42-
`./serve.sh`.
43-
7. Commit your changes.
44-
`git add .`
45-
8. Commit the changes with a descriptive message:
46-
`git commit -m "Fixing typos and improving readability on XXX section"`
47-
9. Push the changes to your forked repository.
48-
`git push origin develop`
49-
10. Create a pull request. Go to your forked repository on GitHub. You should see a "Compare & pull
50-
request" button. Click on it. Provide a descriptive title and description for your pull request.
51-
11. Click on the "Create pull request" button.
52-
12. Wait for review. Once your pull request is approved, and no more changes are needed, we will
53-
merge it into the main repository.
54-
13. Congratulations! Your changes are now part of the security frameworks!
61+
`git clone https://github.com/your-username/frameworks.git`
62+
3. Check if there's a framework-specific branch you should be working on. If yes, use that branch instead of develop.
63+
4. Otherwise, make sure you're in the develop branch:
64+
`git checkout develop`
65+
5. Inside the folder create a new branch based on the appropriate branch:
66+
`git checkout -b your-feature-branch`
67+
6. Make your changes.
68+
7. If adding new pages, consider adding appropriate tags in the frontmatter. Example:
69+
70+
```
71+
---
72+
tags:
73+
- Engineer/Developer
74+
- Security Specialist
75+
- Devops
76+
- SRE
77+
---
78+
```
79+
80+
8. If adding significant content, add attribution using the contributors system (see [using-contributors.md](src/config/using-contributors.md)).
81+
9. Make sure your changes don't break anything by testing it in the local setup:
82+
`just serve`
83+
10. Commit your changes:
84+
`git add .`
85+
11. Commit the changes with a descriptive message:
86+
`git commit -S -m "Fixing typos and improving readability on XXX section"`
87+
12. Push the changes to your forked repository:
88+
`git push origin your-feature-branch`
89+
13. Create a pull request. Go to your forked repository on GitHub. You should see a "Compare & pull request" button. Click on it. Provide a descriptive title and description for your pull request.
90+
14. Click on the "Create pull request" button.
91+
15. Wait for review. Once your pull request is approved, and no more changes are needed, we will merge it into the appropriate branch.
92+
16. Congratulations! Your changes are now part of the security frameworks!
5593
5694
## Editor area
5795
@@ -60,7 +98,4 @@ Editors merge PRs and push suggestions to the main branch which will be reflecte
6098
1. `git checkout main`
6199
2. `git fetch origin develop`
62100
3. `git merge origin/develop`
63-
4. Manually merge files, solve conflicts and add a description.
64-
65-
- Using the `serve.sh` script instead of mdBook `serve` command is needed to be able to see properly
66-
the local deployment.
101+
4. Manually merge files, solve conflicts and add a description.

justfile

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
# Default recipe to display help information
2+
default:
3+
@just --list
4+
5+
# Install dependencies
6+
install:
7+
cargo install mdbook mdbook-admonish
8+
9+
# Serve the book locally with hot reload
10+
serve: install
11+
mdbook serve --hostname 0.0.0.0
12+
13+
# Run all linting checks
14+
lint:
15+
@echo "Running spell check..."
16+
@for f in **/*.md ; do echo $f ; aspell --lang=en_US --mode=markdown --home-dir=. --personal=wordlist.txt --ignore-case=true --camel-case list < $f | sort | uniq -c ; done
17+
@echo "Spell check complete!"
18+
@echo ""
19+
@echo "Running markdownlint..."
20+
markdownlint-cli2 ./src/*.md

serve.sh

Lines changed: 0 additions & 8 deletions
This file was deleted.

src/README.md

Lines changed: 0 additions & 50 deletions
This file was deleted.

0 commit comments

Comments
 (0)