From 27c1826fc52ec655e64143bd078201e3efb80fa0 Mon Sep 17 00:00:00 2001 From: oliver Date: Mon, 4 May 2026 12:53:56 +0800 Subject: [PATCH] docs: add MIT license, security policy, and README updates Generic sample import instructions; expand CONTRIBUTING with upstream remote. Co-authored-by: Cursor --- CONTRIBUTING.md | 15 ++++++++++++--- LICENSE | 21 +++++++++++++++++++++ README.md | 6 +++--- SECURITY.md | 21 +++++++++++++++++++++ 4 files changed, 57 insertions(+), 6 deletions(-) create mode 100644 LICENSE create mode 100644 SECURITY.md diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 1435471..16c57fe 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -4,9 +4,18 @@ ## 流程摘要 -1. Fork 本仓库,克隆你的 Fork。 -2. 基于当前默认分支(一般为 `main`)创建主题分支,例如 `fix/...` 或 `feat/...`。 -3. 提交并推送到你的 Fork,在 GitHub 上向本仓库发起 PR,说明变更内容与测试方式。 +1. **Fork** 本仓库,克隆你的 Fork。 +2. (推荐)添加上游便于同步: + + ```text + git remote add upstream https://github.com/hansjone/netx.git + git fetch upstream + git checkout -b feat/your-topic upstream/main + ``` + +3. 若未添加上游,则基于当前默认分支(一般为 `main`)创建主题分支,例如 `fix/...` 或 `feat/...`。 +4. 提交并推送到你的 Fork:`git push -u origin feat/your-topic` +5. 在 GitHub 上向 `hansjone/netx` 发起 **Pull Request**,说明变更内容与测试方式。 ## 合并前注意 diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..ee91452 --- /dev/null +++ b/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2026 hansjone and contributors + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/README.md b/README.md index c499a0d..c27c408 100644 --- a/README.md +++ b/README.md @@ -2,6 +2,8 @@ Independent operations tool (web + MCP) for alarm-centric workflows. +Licensed under the [MIT License](LICENSE). Security reports: [SECURITY.md](SECURITY.md). + ## Phase 1 scope - Import ZTE Alarm Monitor Excel @@ -142,9 +144,7 @@ Optional: configure oclaw health check endpoint (defaults shown in `.env.example ## Key sample file -Phase 1 parser is tuned for: - -`D:/project/chatgpt/fm-active-Alarm Monitor-CHEN-20260423100105/fm-active-Alarm Monitor-CHEN-20260423100105.xlsx` +Phase 1 parser (`netx_api/config/parsers/zte_alarm_monitor_v1.yaml`) is tuned for **ZTE Alarm Monitor** style exports. Use any local path: place your `.xlsx` on disk and import it from the web UI or API (`POST /v1/alarms/import`). A typical filename pattern is `fm-active-Alarm Monitor-*-YYYYMMDDhhmmss.xlsx` (columns are resolved via YAML aliases, not by absolute path). ## Contributing diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..7ece334 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,21 @@ +# Security policy + +## Supported versions + +Security fixes are applied on the default branch (`main`) when practical. Use the latest commit for deployments. + +## Reporting a vulnerability + +Please **do not** open a public GitHub issue for undisclosed security problems. + +Use **GitHub private vulnerability reporting** for this repository: + +[Submit a private security advisory](https://github.com/hansjone/netx/security/advisories/new) + +Include: + +- A short description of the impact +- Steps to reproduce (or proof-of-concept) if you can share them safely +- Affected API route, UI surface, or dependency (if known) + +We will treat reports as confidential and coordinate a fix and disclosure timeline with you when possible.