The gates are listed in [docs/DEVELOPMENT.md](docs/DEVELOPMENT.md), and the test
pipeline runs the same set.
## AI contribution policy
AI tools are welcome as productivity aids and are a normal part of modern software
development. What matters is that the contribution stays understandable, reviewable and
genuinely useful.
- **Disclose the assistance.** If AI helped draft any part of a commit, issue, pull
request or review, say so.
- **Commit messages carry exactly one trailer**, on the line after the subject:
```
Assisted-by: MODEL
```
Name the model that did the work, spelled the way its maker spells it, for example
`GLM 5.3`, `DeepSeek V4.1 Flash` or `Qwen 3.8 Flash`. No `Co-Authored-By`, no
`Signed-off-by`, no other trailers, and no prose: the trailer is the disclosure.
- **Issues and pull requests** attribute the assistance in a comment, for example
`_Assisted-by: GLM 5.3_`. It does not belong in the pull request description.
- **Take responsibility.** You are accountable for the accuracy, completeness and
intent of everything you submit, whether or not AI produced it.
- **Review before marking ready.** Read the diff carefully, run it locally, and add the
tests it needs. Do not mark a pull request ready until you can defend every change in
it.
- **Quality over quantity.** Contributions that look like un-reviewed output, or whose
author cannot engage substantively during review, may be closed.
- **Preferred models.** Prefer open-weight models with transparent training data and
minimal output filtering.
AI assists. It does not replace judgement.
## Continuous integration
Workflows live in `.gitea/workflows/` and run on the project's own runners:
| Workflow | Trigger | What it does |
|---|---|---|
| Test | push or pull request to `development` | every script compiles, carries its licence header and uses no dash as punctuation, then the six check files under `tests/` |
| Deploy | push to `main` | writes `SHA256SUMS` over every script and publishes them over rsync |
The container rigs are not in the pipeline: they need Podman and a privileged
container, which belong to the machine at the keyboard rather than to a shared runner.
A change to a script that touches a system is expected to be verified that way locally,
and the pull request says what was run.
## Reporting bugs
Open an issue at `https://sourcedock.dev/petrbalvin/scripts/issues` with the script and
its version (the script's `--version`), the operating system and version, the exact
command, the full output, and the expected against the actual behaviour.
**Security issues do not go in the issue tracker.** Report them as