We love contributions! Here's how you can help.
- Use the issue tracker.
- Provide a minimal reproducible example.
- Open a feature request issue.
- Explain the use case and expected behaviour.
- Create a new Python file in
src/sentinel/scanners/sast/detectors/. - Implement a function that takes
(Optional[ast.AST], source, filename)and returns a list of dicts. - Add your function to
DETECTOR_MAPinsrc/sentinel/scanners/sast/engine.py. - Add a corresponding YAML rule in
rules/.
- Fork the repo and create a branch.
- Run
pre-commit install. - Write tests for your changes.
- Update documentation if needed.
- Submit a PR against the
mainbranch.
- Follow PEP 8 (enforced by Ruff).
- Add type hints.
- Keep code coverage above 80%.
The release process for PyPI and Docker is fully automated using GitHub Actions.
To publish a new version:
- Update the version number in
pyproject.toml. - Commit your changes:
git commit -am "Bump version to vX.Y.Z" - Tag the commit with the new version:
git tag vX.Y.Z - Push the commit and the tag to GitHub:
git push origin main && git push origin vX.Y.Z
Pushing the tag will automatically trigger the Publish to PyPI workflow (provided all tests pass). Once that completes successfully, the Docker Build workflow will automatically build and publish the latest Docker image to the registry.
Thank you!