Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion .github/workflows/gitleaks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,9 @@ on:
pull_request:
push:

permissions:
contents: read

jobs:
scan-for-secrets:
name: Run gitleaks
Expand All @@ -14,4 +17,4 @@ jobs:
- name: Check for GitLeaks
uses: gacts/gitleaks@v1
with:
config-path: .github/.gitleaks.toml
config-path: .github/.gitleaks.toml
2 changes: 2 additions & 0 deletions .github/workflows/repoHygieneCheck.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,8 @@ jobs:
{% raw %}
if: needs.check-first-run.outputs.should_run == 'true'
{% endraw %}
permissions:
contents: read
uses: DSACMS/repo-scaffolder/.github/workflows/extendJSONFile.yml@main
with:
url_to_json: 'https://raw.githubusercontent.com/DSACMS/repo-scaffolder/main/tier1/%7B%7Bcookiecutter.project_slug%7D%7D/repolinter.json'
Expand Down
18 changes: 18 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -92,6 +92,24 @@ We also welcome improvements to the project documentation or to the existing
docs. Please file an [issue](https://github.com/{{ cookiecutter.project_org }}/{{ cookiecutter.project_repo_name }}/issues).
-->

## AI Usage

AI tools *(LLMs, coding assistants)* are welcome as part of your contribution workflow, but they don't change who's responsible for the code you submit.

### Recommended uses

- Gaining understanding of the existing code, or solution ideas of the issue
- Translating or proofreading your comments or PR descriptions while keep the wording as close as possible to what you originally wrote

Whenever you use AI in any of these ways, disclose it explicitly in your PR description.

### Not recommended uses

- External AI tooling *(bots, agents)* directly interacting with the project, including creating issues, opening PRs, or commenting on GitHub
- Submitting AI generated code you can't explain line by line to a developer, or using AI output without fully understanding it or verifying it's the correct approach
- Submitting a PR where the effort you put in, such as writing a prompt, is less than the effort it would take a maintainer to review it. We can already write prompts or run automated tools ourselves and doing that directly is faster and more secure than reviewing a low effort PR.
- Using AI to increase the breadth of your contributions, such as spreading yourself across several projects at once. You provide more value by engaging deeply with one or two projects than shallowly with many.

## Policies

### Open Source Policy
Expand Down
Loading