Contributing
Contributions to ainfra should begin with the repository’s contribution and security guidance.
The complete development workflow is maintained in the repository
CONTRIBUTING.md.
The release command boundary is strict. All release lanes must first point to
one exact commit; release-freeze records that commit and tree before any
artifact production:
Do not paste the complete sequence into one terminal. HOST commands run in the normal host checkout; DEVCONTAINER commands run in that checkout’s ainfra devcontainer. Both environments see the same repository files. No second clone, checkout, worktree, or artifact copy is needed, and Go is never installed or invoked on the host.
- HOST: run
release-freezeafter all merges and lane promotions. - DEVCONTAINER: run
release-package. This is the only step that uses Go. It cross-builds four archives and uses Syft to create their SBOMs. A missinggoerror means the command was run on the host; return to the devcontainer instead of installing Go on the host. - HOST: run
release-host-prepare. It needs Git and Python, verifies the packaged artifacts, and does not compile anything. - HOST: run
release-host. It uses uv, Docker, Syft, and Grype to test and inventory the independently built container image. - HOST: run
release-publish --dry-runto preflight credentials and publication. - HOST: run
release-sign, followed by resumablerelease-publish.
Syft therefore belongs in both environments, but it inventories different
subjects. The workspace pins an aibox release whose catalog supplies the
complete supply-chain toolset: Gitleaks, OSV-Scanner, Syft, Grype, and Cosign.
Run aibox apply and rebuild the devcontainer after changing that pin or its
tool selections. Agents must never receive the host Docker socket or
equivalent container-runtime authority. See the repository guide for the
complete commands, prerequisites, and checks.