Skip to content

Found something to improve? Start with the repository or reporting channel that owns it. A small, reproducible report is enough to begin a product discussion.

Contribution or reportDestination
Documentation, examples, public contracts, distribution toolingRootform repository
Official Dialects, Rules, and fixturesdialects/ in Rootform
Command line: commands, flags, help, reports, exit statusescli/ in Rootform
GitHub ActionAction repository
Reproducible product behaviorPublic Rootform issues
Suspected exploitable vulnerabilityPrivate vulnerability reporting

Never use a public issue for an exploitable vulnerability.

Improve a page

Use Edit this page to reach its Markdown source. Keep the change focused and follow Writing for Rootform. Check changed commands against the CLI and show an observable result beside each example.

For a documentation change, run from the Rootform repository:

bun install --frozen-lockfile
bun run check:docs
bun run check:format
Shell

Heading or anchor changes also need a check against the built documentation site. That rendered-HTML check is separate from bun run verify. Follow CONTRIBUTING.md for executable example verification and the complete Rootform repository gate.

Report a semantic gap

Open a public Rootform issue with the Rootform version, a small synthetic example that reproduces the surprise, what you observed, and what you expected. You do not need to classify the internal accounting or know content digests before reporting it.

When relevant, add the provider and version, active Dialect, diagnostic, and provider documentation that supports the expected interpretation. Never include credentials, customer data, state, real plans, or private paths.

To contribute a Rule to an official Dialect, follow Write a Dialect. Include provider documentation, a reproducible fixture, and the behavior it proves under dialects/. A provider-version change needs evidence, not a guessed mapping.

Teams can write their own Policy Packs. Public examples illustrate authoring patterns; they are not an official or community governance catalog.

Contribute to the command line

The Rootform command line is the open-source Go module cli/, under Apache-2.0. It owns the commands, flags, help, completions, argument checks, exit statuses, human and machine reports, the loopback Explorer server, and the HTML export, plus the Form and Policy result models and their schemas. Compilation, Rule evaluation, Policy evaluation, and comparison live in a private engine that implements the module's backend ports; a contribution to cli/ changes how results are asked for and reported, not what they contain.

The module's README explains how to run its tests and the conformance suite with a fake backend. It makes no compatibility promise yet: its version is the commit the engine pins, so open an issue before proposing a change to a command's contract.

Discuss contract changes first

Open an issue before changing a public wire format, CLI contract, release convention, license, or security behavior. Contract text and executable checks must change together. Generated schemas are not hand-edited.

The repository's root license covers source, documentation, contracts, examples, and tooling under Apache-2.0. Official Dialects under dialects/ have their own MPL-2.0 license. Distributed Rootform executables carry an Elastic-2.0 notice.

For reporting instructions, see the security policy.