Contributing to cA2A¶
Thank you for contributing. This document covers everything you need to get started.
Before you start¶
cA2A is a confidential delegation profile on top of A2A. Changes to the delegation chain, sealed channel, attestation path, or TRACE record generation require extra care: these are security-critical components. When in doubt, open an issue first.
Developer certificate of origin¶
All commits must include a Signed-off-by line. This is a lightweight way to certify you wrote the code or have the right to contribute it. No CLA required.
The sign-off certifies the Developer Certificate of Origin v1.1.
Development setup¶
Requires Python 3.11+.
Running checks locally¶
ruff check src/ tests/ # lint
mypy src/ca2a_runtime/ src/ca2a_verify/ # type check
bandit -r src/ -c pyproject.toml # security scan
pytest tests/unit/ -v # unit tests
All four must pass before a PR is mergeable.
Commit format¶
Follow Conventional Commits:
feat: add sealed peer channel handshake
fix: reject child scope that exceeds parent grant
docs: clarify delegation-link fields in the TRACE profile
test: add coverage for cross-chain replay rejection
refactor: extract scope intersection helper
Keep commits small and focused. One logical change per commit. Do not bundle unrelated fixes.
Pull request process¶
- Branch from
main:git checkout -b feat/your-change - Write tests for new behavior: the test suite must pass
- Run all four checks locally (see above)
- Open a PR against
mainwith the template filled in - At least one maintainer must approve before merge
- Squash if the commit history is noisy; preserve meaningful commits
Security-critical components¶
Changes to these paths require two maintainer approvals and a comment explaining the security impact:
src/ca2a_runtime/delegation/: delegation chain verification and scope attenuationsrc/ca2a_runtime/channel/: sealed peer channelsrc/ca2a_runtime/tee/: TEE provider integrationsrc/ca2a_verify/: offline chain and DAG verification
Reporting security vulnerabilities¶
Do not open a public issue. Use GitHub Security Advisories for private disclosure. See SECURITY.md.
Code conventions¶
- Python 3.11+ syntax throughout (
X | Y,match, etc.) ruffenforces style; do not add# noqawithout a comment explaining whymypy --strictonsrc/; new public functions need type annotations- No comments that describe what the code does: only why when non-obvious
- Tests live in
tests/unit/and follow the existingtest_<module>.pynaming
Questions¶
Open a GitHub Discussion for design questions or proposals before writing code.