docs: add CONTRIBUTORS and MAINTAINERS files, update README (#18)

* docs: README update

* docs: introduce CONTRIBUTING.md

* docs: introduce MAINTAINERS.txt
This commit is contained in:
Sahil Bansal
2025-05-11 22:42:27 +05:30
committed by GitHub
parent 86f8bd42b7
commit f7855e99a2
7 changed files with 143 additions and 13 deletions
+78
View File
@@ -0,0 +1,78 @@
# Contributing Guide
You can contribute to `pmg` and help make it better. Apart from bug fixes,
features, we particularly value contributions in the form of:
- Documentation improvements
- Bug reports
- Using `pmg` in your projects and providing feedback
## How to contribute
1. Fork the repository
2. Add your changes
3. Submit a pull request
## How to report a bug
Create a new issue and add the label "bug".
## How to suggest a new feature
Create a new issue and add the label "enhancement".
## Development workflow
When contributing changes to repository, follow these steps:
1. Ensure tests are passing
2. Ensure you write test cases for new code
3. `Signed-off-by` line is required in commit message (use `-s` flag while committing)
## Developer Setup
### Requirements
- Go 1.24+
- Git
- Make
### Getting Started
1. Clone your fork:
```bash
git clone https://github.com/YOUR_USERNAME/pmg.git
cd pmg
```
2. Install dependencies:
```bash
go mod tidy
```
3. Build the project:
```bash
make all
```
### Development Workflow
1. Create a branch:
```bash
git checkout -b feature/your-feature
```
2. Make your changes and test:
```bash
make test
```
3. Commit with sign-off:
```bash
git commit -s -m "feat: add new feature"
```
4. Push and create PR:
```bash
git push origin feature/your-feature
+17
View File
@@ -0,0 +1,17 @@
pmg is built and maintained by SafeDep with the help of the community.
https://safedep.io
Abhisek Datta
Email: abhisek@safedep.io
GitHub username: @abhisek
Affiliation: SafeDep
Sahil Bansal
Email: sahil.bansal@safedep.io
Github username: @Sahilb315
Affiliation: SafeDep
Omkar Phansopkar
Email: omkar.phansopkar@safedep.io
GitHub username: @OmkarPh
Affiliation: SafeDep
+3
View File
@@ -14,3 +14,6 @@ create_bin:
clean:
rm -rf $(BIN_DIR)
test:
go test ./...
+44 -12
View File
@@ -5,13 +5,22 @@ PMG is a security-focused wrapper for package managers that helps detect and pre
## 📑 Table of Contents
- [Features](#features)
- [Supported Ecosystems](#supported-ecosystems)
- [Installation](#installation)
- [Prerequisites](#prerequisites)
- [Environment Variables](#environment-variables)
- [Configuration](#configuration)
- [Usage](#usage)
- [NPM Packages](#npm-packages)
- [PNPM Packages](#pnpm-packages)
- [Common Flags](#common-flags)
- [Contributing](#contributing)
## Features
- 🚫 Malware detection and prevention
- 🌲 Deep dependency analysis
- ⚡ Fast and efficient package verification
- 🔄 Seamless integration with existing package managers
## Supported Ecosystems
Currently, PMG supports the following package ecosystems:
@@ -19,6 +28,7 @@ Currently, PMG supports the following package ecosystems:
| Ecosystem | Status | Command |
|-----------|--------|---------|
| NPM | ✅ Active | `pmg npm install <package>` |
| PNPM | ✅ Active | `pmg pnpm add <package>` |
| PyPI | 🚧 Planned | Coming soon |
| Go | 🚧 Planned | Coming soon |
@@ -35,29 +45,51 @@ go install github.com/safedep/pmg@latest
- Go 1.24
- SafeDep API credentials (SAFEDEP_API_KEY and SAFEDEP_TENANT_ID)
## Environment Variables
## Configuration
- `SAFEDEP_API_KEY`: Your SafeDep API key
- `SAFEDEP_TENANT_ID`: Your SafeDep tenant ID
### Environment Variables
Visit https://docs.safedep.io/cloud/quickstart for instructions on obtaining your API Key and Tenant ID.
| Variable | Description | Required |
|----------|-------------|----------|
| `SAFEDEP_API_KEY` | Your SafeDep API key | Yes |
| `SAFEDEP_TENANT_ID` | Your SafeDep tenant ID | Yes |
Get your API credentials by visiting [SafeDep Quickstart Guide](https://docs.safedep.io/cloud/quickstart).
## Usage
### Scanning NPM packages
### Security in Action
#### Malicious Package Detection
![pmg scan malicious package](./docs/assets/pmg-malicious-pkg.png)
#### Bulk Package Analysis
![pmg scan & install multiple package](./docs/assets/pmg-scan-multiple-pkgs.png)
### NPM Packages
Install a package:
```bash
pmg npm install <package-name>
```
OR
Alternative commands:
```bash
pmg npm i <package-name>
pmg npm i <package-name> # Short form
pmg npm add <package-name> # Alternative syntax
```
OR
### PNPM Packages
Install a package:
```bash
pmg npm add <package-name>
pmg pnpm add <package-name>
```
### Common Flags
All standard package manager flags are supported:
```bash
pmg npm install --save-dev <package-name> # Install as dev dependency
pmg pnpm add -D <package-name> # Install as dev dependency
```
## Contributing
Please feel free to submit a Pull Request.
Refer to [CONTRIBUTING.md](CONTRIBUTING.md)
Binary file not shown.

After

Width:  |  Height:  |  Size: 151 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 293 KiB

+1 -1
View File
@@ -200,7 +200,7 @@ func TestRemoveMarkdown(t *testing.T) {
{"Just plain text", "Just plain text"},
// Complex mixed
{"### Title\nSome **bold** text and a [link](http://url.com).", "Title\nSome bold text and a link."},
{"### Title\nSome **bold** text and a [link](http://url.com).", "Title Some bold text and a link."},
}
for _, tt := range tests {