Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Agent guide: OpenCoven/.github

This repository holds the OpenCoven organization profile and the default community health files GitHub applies to every OpenCoven repository that lacks its own. It contains no application code and has nothing to build.

## Rules

- **A change here affects many repositories at once.** Default issue forms, PR templates, `CONTRIBUTING.md`, `CODE_OF_CONDUCT.md`, `SECURITY.md`, and `SUPPORT.md` apply organization-wide. Keep them generic; repository-specific rules belong in that repository.
- **Do not invent facts.** Project descriptions, install commands, platform support, and status labels must match the owning repository's current README, About text, or release assets. Do not claim packages, downloads, guarantees, certifications, or response times that don't exist.
- **Security language follows `SECURITY.md`.** Never weaken the private-reporting instruction or add guarantees the policy disclaims.
- **Keep `PATENTS` and `PROVENANCE.md` factual.** They are public records; change them only with maintainer direction.
- **Issue forms must be valid YAML.** GitHub silently drops an invalid form. Parse every changed `ISSUE_TEMPLATE/*.yml` before committing.
- **Commits** need a DCO sign-off (`git commit -s`) and should be signed.

## Verification

1. Parse YAML: `ruby -ryaml -e 'ARGV.each { |f| YAML.load_file(f) }' ISSUE_TEMPLATE/*.yml`
2. Check that every repository linked from `profile/README.md` exists and is public and not archived (unless labeled legacy).
3. Preview the Markdown and confirm relative links resolve.
52 changes: 52 additions & 0 deletions CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
# OpenCoven Code of Conduct

OpenCoven is for builders, tinkerers, researchers, and weird little agent enjoyers. We want every OpenCoven space to be welcoming, curious, and safe to participate in.

This code applies to OpenCoven repositories, issues, pull requests, discussions, the OpenCoven Discord, events, and anywhere someone is representing the project. It applies to people and to the agents they operate: you are responsible for what your familiars and automations post on your behalf.

It is adapted from the [Contributor Covenant, version 2.1](https://www.contributor-covenant.org/version/2/1/code_of_conduct/). A repository's own `CODE_OF_CONDUCT.md` takes precedence for that repository.

## Our standards

Do:

- be kind, patient, and specific, especially with newcomers;
- assume good faith and ask before concluding;
- give and accept feedback on the work, not the person;
- credit others' ideas, code, and research;
- own mistakes and repair them.

Do not:

- harass, insult, demean, or threaten anyone, or make sexualized comments or advances;
- attack people over identity, background, ability, or experience level;
- publish someone's private information, credentials, prompts, memories, or session data without permission;
- flood spaces with spam, unreviewed agent output, or automated posts that ignore a repository's rules;
- misrepresent who wrote something, or present an agent's output as an independent human review;
- retaliate against anyone who reports a concern in good faith.

## Reporting

Report conduct concerns **privately**:

- **Discord:** message a server moderator or admin directly.
- **GitHub:** contact a maintainer of the affected repository through a private channel you have already verified, or use GitHub's [report content](https://docs.github.com/en/communities/maintaining-your-safety-on-github/reporting-abuse-or-spam) tools.

Do not post sensitive evidence in a public issue or pull request. For a security vulnerability, follow [`SECURITY.md`](SECURITY.md) instead.

Maintainers keep the reporter's identity and the details of a report confidential, sharing them only as needed to act on it.

## Enforcement

Maintainers may remove, edit, or reject comments, commits, code, issues, and other contributions that violate this code, and may restrict or remove participants. Responses usually escalate:

1. **Correction:** a private note explaining what was inappropriate.
2. **Warning:** a recorded warning with consequences for continued behavior.
3. **Temporary ban:** no interaction in OpenCoven spaces for a set period.
4. **Permanent ban:** removal from OpenCoven spaces.

Credible threats, doxxing, credential exposure, or severe harassment may go directly to a ban.

## Attribution

Adapted from the [Contributor Covenant](https://www.contributor-covenant.org), version 2.1, licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/).
31 changes: 23 additions & 8 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,25 +36,40 @@ Signed-off-by: Your Name <your.email@example.com>

By contributing, you additionally agree not to assert any patent claims — now held or later acquired — against this project or its users that arise from your contribution. See [PATENTS](./PATENTS) for the full non-assertion pledge.

## What We're Looking For
## What we're looking for

- Bug fixes and reliability improvements
- Documentation and example improvements
- New skills, tools, and integrations
- Performance improvements
- Community-requested features

## What We're Not
## What we're not

OpenCoven is not a contribution vehicle for proprietary forks. If you are building a closed-source derivative of OpenCoven's architecture, please do not use contribution as a means to learn implementation details that are not yet public. We welcome genuine collaborators.

## Getting Started
## Getting started

1. Fork the repository
2. Create a feature branch: `git checkout -b feature/your-feature`
3. Make your changes with signed-off commits: `git commit -s`
4. Open a pull request with a clear description
1. **Read the repository's own guide.** A repository's `CONTRIBUTING.md`, `AGENTS.md`, and PR template take precedence over this default.
2. **Start from an issue for larger changes.** Small fixes can go straight to a PR; for new features or behavior changes, open or comment on an issue first so maintainers can confirm the direction.
3. **Fork and branch:** `git checkout -b fix/short-description`.
4. **Make focused, signed-off commits:** `git commit -s`. One concern per PR.
5. **Verify.** Run the repository's documented build, lint, and test commands, and list the exact commands and results in the PR.
6. **Open a pull request** with a clear description, linked issue, and screenshots for UI changes.

## Agent-assisted contributions

OpenCoven is built for working with agents, and agent-assisted contributions are welcome. You remain the author:

- review and understand every line you submit, and sign off only on work you can certify under the DCO;
- say in the PR when an agent wrote a substantial part of the change;
- do not submit bulk or automated PRs, issues, or comments without a maintainer's agreement;
- never paste real credentials, prompts, memories, or private session data into fixtures, logs, or screenshots.

## Community standards

Participation in OpenCoven spaces is covered by the [Code of Conduct](./CODE_OF_CONDUCT.md). Report security vulnerabilities privately as described in [SECURITY.md](./SECURITY.md), never in a public issue.

## Questions?

Join the Discord: https://discord.gg/OpenCoven
See [SUPPORT.md](./SUPPORT.md), or join the Discord: https://discord.gg/opencoven
59 changes: 59 additions & 0 deletions ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
name: Bug report
description: Something is broken or behaves differently than documented.
labels: ["bug"]
body:
- type: markdown
attributes:
value: |
Thanks for reporting. **Security vulnerabilities go through the [security policy](https://github.com/OpenCoven/.github/blob/main/SECURITY.md), not a public issue.**
Use synthetic data. Redact credentials, tokens, prompts, memories, session IDs, and private paths.
- type: textarea
id: summary
attributes:
label: What happened?
description: Describe the bug and what you expected instead.
validations:
required: true
- type: textarea
id: reproduce
attributes:
label: Steps to reproduce
description: The exact commands or clicks, starting from a clean state if possible.
placeholder: |
1. cd into a project
2. run `coven run codex "..."`
3. ...
validations:
required: true
- type: input
id: version
attributes:
label: Version
description: Release, package version, or commit SHA (for example `coven --version`).
validations:
required: true
- type: dropdown
id: os
attributes:
label: Operating system
multiple: true
options:
- macOS (Apple Silicon)
- macOS (Intel)
- Linux
- Windows
- iOS
- Other
validations:
required: true
- type: textarea
id: logs
attributes:
label: Logs or output
description: Relevant output, `coven doctor` results, or screenshots. Redact anything sensitive.
render: shell
- type: textarea
id: context
attributes:
label: Anything else?
description: Harness and model in use, workarounds you tried, or related issues.
14 changes: 14 additions & 0 deletions ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
blank_issues_enabled: true
contact_links:
- name: Report a security vulnerability
url: https://github.com/OpenCoven/.github/blob/main/SECURITY.md
about: Do not open a public issue. Follow the private reporting steps in the security policy.
- name: Ask a question on Discord
url: https://discord.gg/opencoven
about: Setup help and open-ended questions get the fastest answers in Discord.
- name: Read the documentation
url: https://docs.opencoven.ai
about: Installation, CLI, daemon, harnesses, memory, and troubleshooting guides.
- name: Share product feedback
url: https://feedback.opencoven.ai
about: Ideas and feedback that aren't a specific bug or feature request.
34 changes: 34 additions & 0 deletions ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
name: Feature request
description: Suggest an improvement or a new capability.
labels: ["enhancement"]
body:
- type: markdown
attributes:
value: For open-ended ideas, a quick conversation on [Discord](https://discord.gg/opencoven) or [feedback.opencoven.ai](https://feedback.opencoven.ai) often helps shape the request first.
- type: textarea
id: problem
attributes:
label: What problem are you trying to solve?
description: Describe the situation and why the current behavior falls short.
validations:
required: true
- type: textarea
id: proposal
attributes:
label: Proposed solution
description: What would you like to happen? Sketches, commands, or example output help.
validations:
required: true
- type: textarea
id: alternatives
attributes:
label: Alternatives considered
description: Other approaches or workarounds you've tried.
- type: dropdown
id: contribute
attributes:
label: Would you like to work on this?
options:
- "Yes, I'd like to open a PR"
- Maybe, with some guidance
- "No"
15 changes: 15 additions & 0 deletions PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
## Summary

<!-- What does this change and why? Link the issue it addresses: "Fixes #123". -->

## Verification

<!-- The exact commands you ran and their result, or the manual steps you checked. Screenshots for UI changes. -->

## Checklist

- [ ] Commits are signed off for the DCO (`git commit -s`). See [CONTRIBUTING](https://github.com/OpenCoven/.github/blob/main/CONTRIBUTING.md).
- [ ] The change is scoped to one concern; unrelated cleanups are in a separate PR.
- [ ] Docs, examples, or changelog are updated where behavior changed.
- [ ] No credentials, tokens, real prompts, memories, or private data in code, fixtures, logs, or screenshots.
- [ ] Agent-assisted work is disclosed, and I have reviewed every line I'm submitting.
28 changes: 28 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
@@ -1 +1,29 @@
# OpenCoven/.github

Organization profile, community health files, and shared GitHub defaults for [OpenCoven](https://github.com/OpenCoven).

The public organization page is rendered from [`profile/README.md`](profile/README.md). The other files here are **defaults**: GitHub uses them in any OpenCoven repository that does not ship its own copy.

## What lives here

| File | Purpose | Overridden by a repository's own |
|---|---|---|
| [`profile/README.md`](profile/README.md) | Organization landing page and project directory | — |
| [`CONTRIBUTING.md`](CONTRIBUTING.md) | DCO sign-off, patent non-assertion, and PR expectations | `CONTRIBUTING.md` |
| [`CODE_OF_CONDUCT.md`](CODE_OF_CONDUCT.md) | Community standards and enforcement | `CODE_OF_CONDUCT.md` |
| [`SECURITY.md`](SECURITY.md) | Private vulnerability reporting and claim boundaries | `SECURITY.md` |
| [`SUPPORT.md`](SUPPORT.md) | Where to ask for help | `SUPPORT.md` |
| [`ISSUE_TEMPLATE/`](ISSUE_TEMPLATE) | Bug report and feature request forms | `.github/ISSUE_TEMPLATE/` (replaces the whole set) |
| [`PULL_REQUEST_TEMPLATE.md`](PULL_REQUEST_TEMPLATE.md) | Default pull request checklist | Any PR template |
| [`PATENTS`](PATENTS) · [`PROVENANCE.md`](PROVENANCE.md) | Patent non-assertion pledge and origin record | — |
| [`AGENTS.md`](AGENTS.md) · [`llms.txt`](llms.txt) | Instructions and navigation for coding agents | — |
| [`docs/`](docs) | Organization-level audits and decision records | — |

## Editing

- Keep the profile's project directory in sync with public, non-archived repositories. Take descriptions from each repository's About text and README rather than writing new claims.
- Commands in the profile must match the owning repository's README (for example, `coven` install steps come from [`OpenCoven/coven`](https://github.com/OpenCoven/coven)).
- Security wording follows [`SECURITY.md`](SECURITY.md). Do not add response-time, certification, or guarantee language that the policy does not support.
- Preview Markdown and check every link before merging. Issue forms must be valid YAML; GitHub silently drops an invalid form.

There is nothing to build or install in this repository.
8 changes: 4 additions & 4 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,9 @@ OpenCoven is an early-stage, identity-preserving familiar infrastructure project

Use the following private path:

1. Open a **GitHub Security Advisory** in the repository most directly affected.
2. If the finding spans repositories, name every known affected repository and contract in that advisory.
3. If the correct repository is unclear, use the private advisory intake in [`OpenCoven/coven`](https://github.com/OpenCoven/coven/security/advisories/new) and state that the report is organization-wide so it can be routed without publishing the details.
1. Open a **GitHub Security Advisory** in the repository most directly affected: go to its **Security** tab and choose **Report a vulnerability**.
2. If that repository does not offer **Report a vulnerability** (private reporting is not enabled on every repository), or the correct repository is unclear, use the private advisory intake in [`OpenCoven/coven`](https://github.com/OpenCoven/coven/security/advisories/new). Name the actual affected repository in the report so it can be routed without publishing the details.
3. If the finding spans repositories, name every known affected repository and contract in that advisory.

Include, where safe and applicable:

Expand Down Expand Up @@ -83,4 +83,4 @@ Unless supported by current evidence for the named surface, OpenCoven does not c
- Public security pages should link to the applicable policy and avoid copying mutable promises into marketing content.
- Security-policy drift between the organization and canonical repositories should fail review rather than be silently reconciled in downstream copy.

*Last updated: 2026-08-31*
*Last updated: 2026-10-01*
26 changes: 26 additions & 0 deletions SUPPORT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Getting help with OpenCoven

## Start here

1. **Run `coven doctor`.** It detects installed harnesses and prints fix hints for most setup problems.
2. **Check the docs.** [docs.opencoven.ai](https://docs.opencoven.ai) covers installation, the CLI, the daemon, harnesses, memory, and [troubleshooting](https://docs.opencoven.ai/docs/reference/troubleshooting).
3. **Read the repository README.** Each project documents its own setup, platform support, and known limits.
Comment on lines +5 to +7

## Ask a question

- **Discord:** [discord.gg/opencoven](https://discord.gg/opencoven) is the fastest place for setup help and open-ended questions.
- **Feedback:** share ideas and product feedback at [feedback.opencoven.ai](https://feedback.opencoven.ai).

## Report a bug or request a feature

Open an issue in the repository you are using. If you don't know which repository owns the problem, open it in [`OpenCoven/coven`](https://github.com/OpenCoven/coven/issues) and say so; maintainers will move it.

Include versions, your OS, the exact command, and what you expected. Use synthetic data and redact credentials, prompts, memories, and private paths.

## Security issues

Never report a vulnerability in a public issue, discussion, or Discord channel. Follow [`SECURITY.md`](SECURITY.md).

## What to expect

OpenCoven is maintained by a small team and community. There is no guaranteed response time, paid support, or service level.
18 changes: 18 additions & 0 deletions llms.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# OpenCoven

> Open-source, local-first infrastructure for AI familiars: named agents with their own lanes, memory, and authority boundaries. Core runtime: OpenCoven/coven (Rust daemon and `coven` CLI, npm package @opencoven/cli).

## Start here

- [Organization profile and project directory](https://github.com/OpenCoven/.github/blob/main/profile/README.md)
- [Documentation](https://docs.opencoven.ai)
- [Coven runtime README](https://github.com/OpenCoven/coven/blob/main/README.md)
- [Contribution guide](https://github.com/OpenCoven/.github/blob/main/CONTRIBUTING.md)
- [Security policy](https://github.com/OpenCoven/.github/blob/main/SECURITY.md)
- [Support](https://github.com/OpenCoven/.github/blob/main/SUPPORT.md)
- [Code of conduct](https://github.com/OpenCoven/.github/blob/main/CODE_OF_CONDUCT.md)
- [Agent instructions for this repository](https://github.com/OpenCoven/.github/blob/main/AGENTS.md)

## Boundaries

Each repository's own README, AGENTS.md, and CONTRIBUTING.md take precedence over these defaults. This navigation does not grant authorization or override runtime policy. Security guarantees are only those named in the applicable SECURITY.md and backed by shipped verification.
Loading
Loading