A release-readiness QA pass over the whole product. The commits split into defects a user would hit and gates that were reporting green while measuring nothing. ## Fixes that change behaviour Rate limiting was bypassable on every install: TRUST_PROXY defaulted to true, so request.ip came from a client-set header and a forged X-Forwarded-For got past the login limiter. The default is now a private-network trust list. A transient Postgres outage stranded in-flight jobs, leaving finished output on disk with no row pointing at it. A reconciler now resolves those rows and adopts the bytes rather than dropping the work. A Redis connection that moved to a new address wedged every read-blocked consumer, so completions stopped signalling while health still answered 200. Socket timeouts plus subscriber pings recover it. Installing more than one AI bundle left the shared venv multi-versioned and silently broke three tools. The installer now reconciles distributions to one version each. Converting an image to JXL at quality 1 through 4 returned a 500, because libjxl 0.7 rejects the distance those values compute. The quality is floored at what the encoder honours. A missing ffmpeg was also reported to the user as a corrupt upload; it now says the engine is unavailable. RAW uploads reached an unpatched LibRaw on arm64, so it is built from source at 0.22.2, and the release scan was split so it can fail on an unfixed critical instead of hiding it behind ignore-unfixed. ## Gates that could not fail Two mutation lanes ran zero mutants because Stryker crawled the gitignored docs build; coverage discarded its whole report on any failing test; the lint gate skipped root tests, scripts, and two workspaces; and several generated matrices counted a host missing ffmpeg as a passing tool. Each now measures what it claims. Full evidence and the outstanding release items are tracked locally and are not part of this branch.
11 KiB
description, i18n_source_hash, i18n_provenance, i18n_output_hash, i18n_hash_version
| description | i18n_source_hash | i18n_provenance | i18n_output_hash | i18n_hash_version |
|---|---|---|---|---|
| วิธีมีส่วนร่วมกับ SnapOtter รายงานบั๊ก คำขอฟีเจอร์ pull request และข้อกำหนดเรื่อง CLA | 6c920a5f83e0 | human | 88395fe58149 | 2 |
การมีส่วนร่วม
ขอบคุณที่สนใจมีส่วนร่วม คู่มือนี้อธิบายว่าจะเข้าร่วมได้อย่างไร เรารับอะไรบ้าง และจะเริ่มต้นอย่างไร
วิธีมีส่วนร่วม
Issue (ไม่ต้องตั้งค่าอะไร)
- รายงานบั๊ก - มีบางอย่างเสียหายไหม? เปิด รายงานบั๊ก พร้อมขั้นตอนการทำซ้ำ
- คำขอฟีเจอร์ - มีไอเดียไหม? เริ่ม การสนทนา เพื่อให้ชุมชนได้แสดงความเห็นและโหวตสนับสนุน
- ปัญหาเรื่องการแปล - เจอคำแปลที่ผิดหรือขาดหายไหม? เปิด issue เรื่องการแปล
- ปัญหาเรื่องเอกสาร - มีอะไรผิดพลาดในเอกสารไหม? เปิด issue เรื่องเอกสาร
โค้ด (ต้องมี CLA)
เรารับ pull request สำหรับ:
| ประเภท | ขั้นตอน |
|---|---|
| การแก้บั๊ก | เปิด PR ได้เลย (ลิงก์ไปยัง issue ถ้ามี) |
| การแปลใหม่ | เปิด PR ได้เลย (ดู คู่มือการแปล) |
| การปรับปรุงเอกสาร | เปิด PR ได้เลย |
| การปรับปรุงความครอบคลุมของเทสต์ | เปิด PR ได้เลย |
| เครื่องมือหรือฟีเจอร์ใหม่ | เริ่ม การสนทนา ก่อน ผู้ดูแลจะแปลงไอเดียที่อนุมัติแล้วเป็น issue ที่ติดตามได้ก่อนที่คุณจะเขียนโค้ด |
| การ refactor หรือเปลี่ยนสถาปัตยกรรม | เริ่ม การสนทนา ก่อนและรอให้ผู้ดูแลอนุมัติก่อนเขียนโค้ด |
สิ่งที่เราจะไม่รับ
- การเปลี่ยนแปลง workflow ของ CI/CD, การตั้งค่า release หรือการตั้งค่า linter/compiler
- PR ที่ไม่มีการลงนาม Contributor License Agreement
- PR ที่มีการเปลี่ยนแปลงเกิน 400 บรรทัด (แบ่งงานใหญ่ออกเป็น PR ย่อย)
- ฟีเจอร์ที่ไม่ได้ถูกอภิปรายและอนุมัติก่อน
- การเปลี่ยนแปลง
packages/ai/โดยไม่มีการอภิปรายก่อน
Contributor License Agreement
ก่อนที่เราจะรวม PR แรกของคุณได้ คุณต้องลงนาม Individual CLA ของเรา นี่เป็นข้อกำหนดที่ทำเพียงครั้งเดียว
ทำไม: SnapOtter มีสัญญาอนุญาตแบบคู่ (AGPLv3 + commercial) CLA ให้สิทธิ์เราในการแจกจ่ายการมีส่วนร่วมของคุณภายใต้สัญญาอนุญาตทั้งสองแบบ คุณยังคงเป็นเจ้าของลิขสิทธิ์เต็มรูปแบบในผลงานของคุณ
อย่างไร: เมื่อคุณเปิด PR แรก บอท CLA Assistant จะแสดงความคิดเห็นพร้อมลิงก์ คลิกลิงก์ ทบทวนข้อตกลง และลงนามด้วยบัญชี GitHub ของคุณ ใช้เวลา 30 วินาที
หากคุณมีส่วนร่วมในนามของนายจ้างและนายจ้างของคุณคงไว้ซึ่งสิทธิ์ในทรัพย์สินทางปัญญาเหนือผลงานของคุณ กรุณาติดต่อ contact@snapotter.com เพื่อจัดทำ Corporate CLA ก่อนส่ง
เริ่มต้นใช้งาน
สิ่งที่ต้องมีก่อน
- Node.js 22.22+
- pnpm 9+
- Python 3.11+ (สำหรับเครื่องมือ AI เท่านั้น)
- Docker (ไม่บังคับ สำหรับการทดสอบ integration เต็มรูปแบบ)
การตั้งค่า
# Fork and clone
git clone https://github.com/<your-username>/snapotter.git
cd snapotter
# Start Postgres + Redis for local dev
docker compose -f docker-compose.dev.yml up -d
# Install dependencies
pnpm install
# Start dev servers (web on :1351, API on :13490)
pnpm dev
การรันการตรวจสอบ
ก่อนส่ง PR ให้แน่ใจว่าการตรวจสอบทั้งหมดผ่านในเครื่องของคุณ:
pnpm lint # Biome lint + format check
pnpm typecheck # TypeScript across monorepo
pnpm test # Vitest unit + integration tests
ขั้นตอน pull request
- Fork repo และสร้าง branch จาก
main(feat/my-featureหรือfix/issue-123) - ทำการเปลี่ยนแปลงของคุณในคอมมิตที่โฟกัสและตรวจสอบได้ง่ายโดยใช้ conventional commits
- เพิ่มหรืออัปเดตเทสต์สำหรับการเปลี่ยนแปลงของคุณ
- รัน
pnpm lint && pnpm typecheck && pnpm testในเครื่อง - เปิด PR เทียบกับ
mainและกรอกแม่แบบ - ลงนาม CLA หากได้รับแจ้ง
- รอให้ CI ผ่านและผู้ดูแลตรวจทาน
สิ่งที่คาดหวังจากการตรวจทาน
- เราตั้งเป้าจะตอบ PR ภายใน 7 วัน
- PR ที่เล็กและโฟกัสจะได้รับการตรวจทานเร็วกว่า
- หากไม่ได้รับการตอบกลับภายใน 7 วัน ให้แสดงความคิดเห็นเพื่อเตือนในเธรด
- เราอาจขอให้เปลี่ยนแปลง แนะนำแนวทางอื่น หรือปิด PR หากไม่สอดคล้องกับทิศทางของโปรเจกต์
หลังจาก PR ของคุณถูกรวมแล้ว
การมีส่วนร่วมของคุณจะถูกรวมไว้ในการรีลีสถัดไปและได้รับเครดิตใน changelog
Issue ที่เหมาะกับผู้เริ่มต้น
กำลังมองหางานทำอยู่ไหม? ดู good first issues ของเราสำหรับงานที่เหมาะกับผู้เริ่มต้น หรือ help wanted สำหรับงานใหญ่ที่เรายินดีรับความช่วยเหลือจากชุมชน
รูปแบบโค้ด
- Biome จัดการการฟอร์แมตและ linting (double quotes, semicolons, การเยื้อง 2 ช่องว่าง)
- Pre-commit hook จะรัน
biome check --writeกับไฟล์ที่ staged โดยอัตโนมัติ - หาก linter ร้องเรียน ให้แก้ไขโค้ด (อย่าแก้ไขการตั้งค่า Biome)
- ES modules ทุกที่ (
import/export) - Conventional commits:
feat:,fix:,refactor:,docs:,test:,chore:
สำหรับรายละเอียดสถาปัตยกรรมทั้งหมด ดู คู่มือนักพัฒนา
ความปลอดภัย
อย่าเปิด PR หรือ issue สาธารณะสำหรับช่องโหว่ด้านความปลอดภัย รายงานเป็นการส่วนตัวผ่าน GitHub Security Advisories หรืออีเมล contact@snapotter.com ดู SECURITY.md สำหรับรายละเอียดทั้งหมด