diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..2f85646 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,3 @@ +# Every change needs a review from the maintainer before it can be merged +# (enforced by the "Require review from Code Owners" branch rule on main). +* @vij-sameerb5 diff --git a/.github/ISSUE_TEMPLATE/bug_report.yml b/.github/ISSUE_TEMPLATE/bug_report.yml new file mode 100644 index 0000000..e2a9429 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.yml @@ -0,0 +1,35 @@ +name: Bug report +description: Something in JevX (CLI, MCP or the Chrome extension) didn't work +labels: ["bug", "needs-triage"] +body: + - type: dropdown + id: where + attributes: + label: Where did it happen? + options: ["CLI (jevx)", "MCP (Claude Code / Desktop / Cursor …)", "Chrome extension", "Website"] + validations: { required: true } + - type: input + id: version + attributes: + label: Version + description: "`jevx --version`, or the extension version from chrome://extensions" + validations: { required: true } + - type: textarea + id: what + attributes: + label: What happened, and what did you expect? + description: The command or steps, the output, and what you expected instead. + validations: { required: true } + - type: textarea + id: logs + attributes: + label: Output or screenshots + description: Please remove any API keys, tokens or private code first. + render: shell + - type: checkboxes + id: privacy + attributes: + label: Before you submit + options: + - label: I removed API keys, tokens and private code from everything above + required: true diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml new file mode 100644 index 0000000..94886f6 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -0,0 +1,8 @@ +blank_issues_enabled: false +contact_links: + - name: Security problem (keys or code could leak) + url: https://github.com/vij-sameerb5/JevX/security/advisories/new + about: Please report privately, not as a public issue. + - name: Docs and setup help + url: https://jevx.live/docs.html + about: Install, MCP setup and every command. diff --git a/.github/ISSUE_TEMPLATE/feature_request.yml b/.github/ISSUE_TEMPLATE/feature_request.yml new file mode 100644 index 0000000..6eb421a --- /dev/null +++ b/.github/ISSUE_TEMPLATE/feature_request.yml @@ -0,0 +1,19 @@ +name: Feature request +description: An idea for JevX +labels: ["enhancement", "needs-triage"] +body: + - type: textarea + id: problem + attributes: + label: What problem would this solve? + validations: { required: true } + - type: textarea + id: idea + attributes: + label: What would you like JevX to do? + validations: { required: true } + - type: textarea + id: example + attributes: + label: An example + description: A code snippet, repo or command where this would help (no private code). diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md new file mode 100644 index 0000000..aa7d286 --- /dev/null +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -0,0 +1,28 @@ +## What this changes + + + +## Why + + + +## How I checked it + +- [ ] `pnpm test` passes +- [ ] `pnpm typecheck` and `pnpm lint` pass +- [ ] Added or updated a test for this change +- [ ] Tried it on a real repo (say which): + +## Safety checklist + +- [ ] No API keys, tokens, `.env` files or personal data in the diff +- [ ] Nothing new is sent off the user's machine (or it's opt-in and documented) +- [ ] If a prompt changed: bumped `ENGINE_PROMPT_VERSION` +- [ ] Added a line under "Unreleased" in `apps/jevx/CHANGELOG.md` + +## Screenshots / output + + + +--- +Only the maintainer (@vij-sameerb5) merges pull requests. Thanks for contributing! diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..c0de2de --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,46 @@ +# Runs on every pull request and every push to main. +# Make "CI / checks" a required status check so nothing broken can be merged. +name: CI + +on: + pull_request: + push: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ci-${{ github.ref }} + cancel-in-progress: true + +jobs: + checks: + name: checks + runs-on: ubuntu-latest + timeout-minutes: 20 + env: + # tests use local mocks only; no real API keys are needed (and none are set) + CI: "1" + steps: + - uses: actions/checkout@v4 + - uses: pnpm/action-setup@v4 + - uses: actions/setup-node@v4 + with: + node-version: 22 + cache: pnpm + - name: Install + run: pnpm install --frozen-lockfile + - name: Typecheck + run: pnpm typecheck + - name: Lint + run: pnpm lint + - name: Test + run: pnpm test + - name: Build the CLI + run: pnpm build + - name: No secrets in the package + run: | + if grep -rEn 'xai-[A-Za-z0-9]{20,}|sk-(or-|proj-|ant-)?[A-Za-z0-9_-]{24,}|github_pat_[A-Za-z0-9_]{30,}|AIza[0-9A-Za-z_-]{30,}' apps/jevx/dist apps/jevx-extension --include=*.js --include=*.json; then + echo "Key-like string found"; exit 1 + fi diff --git a/.gitmessage b/.gitmessage new file mode 100644 index 0000000..b6952cf --- /dev/null +++ b/.gitmessage @@ -0,0 +1,7 @@ +# : +# +# Why this change was needed (wrap at 72 characters). +# +# Fixes # +# +# Types: feat · fix · docs · test · refactor · chore · perf diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index f3a5bc5..ee1461f 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -56,3 +56,9 @@ plus the relevant `.jevx/debug/*.json` (check them for anything private first). ## Security Found a way JevX could leak code or keys? Please use GitHub's private vulnerability reporting (Security → Report a vulnerability) instead of a public issue. + +## Reviews and merging + +- Every pull request is reviewed by the maintainer (@vij-sameerb5), who is the only one who merges. `main` is protected. +- Use the pull request template. Keep one change per PR, with a test. +- Commit messages: `git config commit.template .gitmessage` gives you the format (`fix: …`, `feat: …`). diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..65601c4 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,5 @@ +# Security + +Found a way JevX could leak code, API keys or tokens? Please **don't open a public issue**. + +Report it privately: [Security → Report a vulnerability](https://github.com/vij-sameerb5/JevX/security/advisories/new). You'll get a reply within a few days. diff --git a/package.json b/package.json index 788e829..3bfc31d 100644 --- a/package.json +++ b/package.json @@ -7,7 +7,7 @@ }, "scripts": { "dev": "tsx apps/jevx/src/index.ts --welcome", - "build": "pnpm --filter jevx --filter jevx-lab build", + "build": "pnpm --filter @vij-sameerb5/jevx --filter jevx-lab build", "jevx": "tsx apps/jevx/src/index.ts", "typecheck": "tsc -p tsconfig.json --noEmit", "test": "vitest run", diff --git a/scripts/study-jev-repos.mjs b/scripts/study-jev-repos.mjs index e93e7ff..de6f659 100644 --- a/scripts/study-jev-repos.mjs +++ b/scripts/study-jev-repos.mjs @@ -6,7 +6,7 @@ // // The token is read from the environment only and never printed or saved. import { execFileSync } from "node:child_process"; -import { mkdirSync, readFileSync, readdirSync, rmSync, statSync, writeFileSync, existsSync } from "node:fs"; +import { mkdirSync, readFileSync, readdirSync, writeFileSync, existsSync } from "node:fs"; import path from "node:path"; const DEFAULT = [ @@ -27,15 +27,13 @@ const gh = (url, out) => { const cfg = `header = "Authorization: Bearer ${token}"\nheader = "User-Agent: jevx-study"\nheader = "Accept: application/vnd.github+json"\n`; try { return execFileSync("curl", ["-sSL", "--fail", "--max-time", "150", "--config", "-", ...(out ? ["-o", out] : []), url], { input: cfg, maxBuffer: 64 << 20, stdio: ["pipe", "pipe", "ignore"] }).toString(); - } catch (e) { throw new Error(`download failed (curl exit ${e.status})`); } + } catch (e) { throw new Error(`download failed (curl exit ${e.status})`, { cause: e }); } // the token is on stdin, so the cause never contains it }; const OUT = path.resolve("dataset/jev-community"); mkdirSync(OUT, { recursive: true }); const SRC = /\.(ts|tsx|js|jsx|mjs|cjs|py|go|rs|java|kt|swift|rb)$/; const SKIP = /(^|\/)(node_modules|dist|build|vendor|\.next|coverage|__pycache__|\.venv|venv)\//; -// Jev usage signals: SDK imports, the System One call, the three primitives -const SIGNAL = /systemOne|system_one|@typesafe-ai\/sdk|from typesafe|import typesafe|TypeSafeClient|\bnoul\s*\(|\bchoice\s*\(|\bscore\s*\(|typesafe\.ai/i; const PRIM = (s) => (/\bnoul\b/i.test(s) ? "noul" : /\bchoice\b/i.test(s) ? "choice" : /\bscore\b/i.test(s) ? "score" : "call"); const CTX = 30;