Contributing to Vendune
This is an experimental commerce and migration laboratory. Changes should keep merchant authority, tenant isolation and deterministic commerce operations explicit.
Start locally
Follow the quickstart. You can explore commerce without Ollama or cloud API keys. Use synthetic shops and simulated payments for tests.
Report a bug
Use the bug-report issue form. Include the commit/version, operating system, setup path, exact steps and expected versus observed output. Remove private credentials and customer data from logs. Security-sensitive findings should follow the security scope, not a public issue containing secrets.
Propose a change
Open an issue describing the user problem and the smallest useful change. Good first contributions include setup documentation, locale corrections, reproducible commerce bugs and small behavior ports. Do not advertise an unimplemented protocol or production capability in documentation.
For new payment rails, read the provider contribution requirements. App installation alone does not register a settlement provider; contributions must integrate invoice-bound verification, reconciliation and the core ledger.
Validate proportionally
For documentation/site changes:
python3 -m pip install -r site/requirements.txt
python3 scripts/build_site.py
python3 scripts/check_site.py
For frontend changes, run npm ci, npm run format:check and npm run build
from frontend/. For Rust changes, use cargo fmt --check,
cargo clippy --locked --all-targets -- -D warnings and cargo test --locked.
Run the relevant application suites from the testing guide
against your own instance. Original Shopware ports require original-source
comparisons described in the migration workflow.
Formal contracts and source review
All Rust modules, schema/build inputs and proof tooling are recorded in
proof/manifest.json. A changed/new module requires a deliberate review record;
CI does not silently refresh it. For policy changes also update the generated
model, exact theorem, production binding and representative negative mutation.
Do not weaken a contract merely to make an incorrect change pass.
python3 scripts/formal.py --generate --record-review 'Explain the reviewed change and relevant regression evidence'
python3 scripts/formal/mutations.py
python3 scripts/formal.py
Read the Lean guide for installation and the
precise boundary. Unproved modules remain unproved after hash review; only the
specified extracted policies have Lean proofs. Pull requests must pass the
required verify check, including the formal gate and real integration suites.
Pull requests
Describe the concrete before/after behavior, relevant checks and remaining
limits. Keep unrelated changes out of the diff. Do not commit .env, provider
keys, session tokens, private data or dependency/build directories.
Contributions are made under the Vendune Sustainable Use License. Vendune is source available; own-business stores are permitted, while commercial shop platforms, managed hosting and SaaS for independent merchants require separate written permission. Preserve upstream licenses and copyright notices. You retain ownership of your contribution; no copyright transfer or blanket relicensing consent is implied. See the licensing guide.