Feature Requirements: phase-1-community-governance
Metadata
- Feature: phase-1-community-governance
- Status: APPROVED
- Created: 2026-02-07T16:20:00
- Author: Factory Plan Mode
- Parent Epic: #179 (ZERG Public Release)
- Issues: #185, #186, #187, #188
1. Problem Statement
1.1 Background
ZERG is preparing for public release as zerg-ai on PyPI. Phase 0 (blockers) is complete — distribution renamed, CHANGELOG frozen, TestPyPI validated, GitHub environments and branch protection configured. The repo is currently private.
1.2 Problem
The repo lacks standard open-source community infrastructure: issue templates, PR template, Code of Conduct, Dependabot config, README badges, and GitHub topics. Without these, contributors see an incomplete project and have no structured way to report bugs or submit PRs.
1.3 Impact
Without Phase 1:
- Bug reports lack reproducibility info (no template)
- PRs have inconsistent descriptions (no template)
- No Code of Conduct signals unclear community standards
- No badges means no at-a-glance project health
- No topics means poor GitHub discoverability
- No Dependabot means dependency vulnerabilities go unnoticed
2. Users
2.1 Primary Users
- Open-source contributors who want to file issues or submit PRs
- Developers evaluating ZERG from the GitHub repo page
2.2 Secondary Users
- Maintainer (rocklambros) — benefits from structured issue reports and consistent PRs
2.3 User Stories
- As a contributor, I want issue templates so that I provide the right information in bug reports
- As a contributor, I want a PR template so that I know what to include in my pull requests
- As a visitor, I want README badges so that I can assess project health at a glance
- As a maintainer, I want Dependabot so that I'm alerted to vulnerable dependencies
3. Functional Requirements
3.1 Core Capabilities
| ID |
Requirement |
Priority |
Issue |
Notes |
| FR-001 |
Bug report issue template (YAML form) |
Must |
#185 |
Fields: description, repro steps, expected/actual, environment, logs |
| FR-002 |
Feature request issue template (YAML form) |
Must |
#185 |
Fields: problem statement, proposed solution, alternatives, context |
| FR-003 |
Issue template config.yml |
Must |
#185 |
Disable blank issues, link to Discussions for questions, link to SECURITY.md |
| FR-004 |
Pull request template |
Must |
#186 |
Sections: Summary, Changes, Test Plan, Checklist |
| FR-005 |
CODE_OF_CONDUCT.md |
Must |
#186 |
Contributor Covenant v2.1 |
| FR-006 |
Dependabot config |
Must |
#187 |
pip ecosystem, weekly schedule |
| FR-007 |
Enable secret scanning |
Must |
#187 |
Via GitHub API |
| FR-008 |
Enable push protection |
Should |
#187 |
Via GitHub API |
| FR-009 |
README badges |
Must |
#188 |
PyPI version, Python version, License, CI status |
| FR-010 |
GitHub topics |
Must |
#188 |
claude-code, parallel-execution, ai-coding, etc. |
| FR-011 |
License compatibility audit |
Should |
#188 |
Verify all deps are MIT/BSD/Apache compatible |
| FR-012 |
Update SECURITY.md supported versions |
Must |
— |
Add 0.2.x, reflect current state |
3.2 Inputs
- Issue template YAML specs
- Contributor Covenant v2.1 text
- Dependabot config YAML
- Badge markdown from shields.io
3.3 Outputs
- 6 new files: 3 issue templates, 1 PR template, 1 CoC, 1 Dependabot config
- 2 modified files: README.md (badges), SECURITY.md (versions)
- GitHub API changes: topics, secret scanning, push protection
3.4 Business Rules
- Issue templates use YAML format (renders as forms in GitHub UI)
- Bug report requires: description, repro steps, ZERG version
- Feature request requires: problem statement, proposed solution
- PR template checklist references existing CI requirements
- CoC enforcement contact: use GitHub Security Advisories (no personal email)
4. Non-Functional Requirements
4.1 Performance
N/A — configuration files only, no runtime impact
4.2 Security
- Secret scanning enabled to catch leaked API keys
- Push protection enabled to block commits containing secrets
- Dependabot alerts for dependency vulnerabilities
4.3 Reliability
N/A — static files
4.4 Scalability
N/A — static files
5. Scope
5.1 In Scope
- GitHub issue templates (bug, feature, config)
- PR template
- CODE_OF_CONDUCT.md (Contributor Covenant v2.1)
- Dependabot configuration
- Secret scanning + push protection enablement
- README badges (PyPI, Python, License, CI)
- GitHub repository topics
- License compatibility audit
- SECURITY.md version table update
5.2 Out of Scope
- CodeQL workflow (deferred to Phase 2, #189)
- mypy in CI (deferred to Phase 2, #189)
- mkdocs documentation site (deferred to Phase 2, #190)
- GitHub Discussions setup (already enabled)
- Terminal demo / social preview (deferred to Phase 3, #191)
- Making repo public (separate decision, not part of this spec)
5.3 Assumptions
- Repo stays private during Phase 1 (go-public is a separate step)
- Badges will show "not found" until repo is public — that's fine
- Dependabot alerts are already enabled (confirmed via API)
- Branch protection is already configured from Phase 0
5.4 Constraints
- Must use Contributor Covenant v2.1 (standard, widely recognized)
- Issue templates must use YAML format (not markdown) for form rendering
- All changes must pass existing CI (quality, smoke, test, audit)
6. Dependencies
6.1 Internal Dependencies
| Dependency |
Type |
Status |
| Phase 0 (blockers) |
Required |
Complete |
| Branch protection |
Required |
Complete (5 checks configured) |
| CONTRIBUTING.md |
Reference |
Exists |
| SECURITY.md |
Reference |
Exists (needs version update) |
6.2 External Dependencies
| Dependency |
Type |
Owner |
| shields.io |
Badge rendering |
External service |
| GitHub API |
Repo settings |
GitHub |
| Contributor Covenant |
CoC text |
contributorcovenant.org |
7. Acceptance Criteria
7.1 Definition of Done
7.2 Test Scenarios
| ID |
Scenario |
Given |
When |
Then |
| TC-001 |
Bug report template |
Repo has templates |
User clicks "New Issue" |
Bug report form renders with required fields |
| TC-002 |
Feature request template |
Repo has templates |
User clicks "New Issue" |
Feature request form renders |
| TC-003 |
Blank issue blocked |
config.yml disables blank |
User tries blank issue |
Redirected to templates or Discussions |
| TC-004 |
PR template |
Template exists |
User opens new PR |
Description pre-filled with template |
| TC-005 |
Dependabot |
Config exists |
Dependency has CVE |
Dependabot opens alert/PR |
| TC-006 |
Badges |
Badges in README |
User views README |
Badges visible with correct links |
7.3 Success Metrics
- All 4 issues (#185-#188) closeable
- Zero new files outside
.github/ and project root
- No runtime code changes
8. Open Questions
| ID |
Question |
Owner |
Status |
| Q-001 |
Should we enable "require linear history" (squash-only merges)? |
maintainer |
Resolved: No — allow merge commits |
| Q-002 |
What email/contact for CoC enforcement? Use GH Security Advisories link? |
maintainer |
Resolved: Yes — use GitHub Security Advisories |
9. Approval
| Role |
Name |
Date |
Signature |
| Product |
rocklambros |
|
PENDING |
10. Documentation
After implementation:
- CHANGELOG.md updated with Phase 1 entries (ALWAYS required)
- README.md updated with badges
- SECURITY.md version table updated
- CONTRIBUTING.md may need minor link updates (to PR template, CoC)
11. Documentation Impact Analysis
11.1 Files Requiring Documentation Updates
| File |
Current State |
Required Update |
Priority |
CHANGELOG.md |
Has [Unreleased] |
Add Phase 1 entries |
Must |
README.md |
No badges |
Add badge row at top |
Must |
SECURITY.md |
Shows 0.1.x only |
Add 0.2.x to supported versions |
Must |
CONTRIBUTING.md |
Exists, complete |
Link to CoC if not already linked |
Should |
11.2 Documentation Tasks for Design Phase
1---2name: feature-requirements-phase-1-community-governance3description: ZERG is preparing for public release as zerg-ai on PyPI. Phase 0 (blockers) is complete — distribution renamed, CHANGELOG frozen, TestPyPI validated, GitHub environments and branch protection configured.4---5# Feature Requirements: phase-1-community-governance67## Metadata8- **Feature**: phase-1-community-governance9- **Status**: APPROVED10- **Created**: 2026-02-07T16:20:0011- **Author**: Factory Plan Mode12- **Parent Epic**: #179 (ZERG Public Release)13- **Issues**: #185, #186, #187, #1881415---1617## 1. Problem Statement1819### 1.1 Background20ZERG is preparing for public release as `zerg-ai` on PyPI. Phase 0 (blockers) is complete — distribution renamed, CHANGELOG frozen, TestPyPI validated, GitHub environments and branch protection configured. The repo is currently private.2122### 1.2 Problem23The repo lacks standard open-source community infrastructure: issue templates, PR template, Code of Conduct, Dependabot config, README badges, and GitHub topics. Without these, contributors see an incomplete project and have no structured way to report bugs or submit PRs.2425### 1.3 Impact26Without Phase 1:27- Bug reports lack reproducibility info (no template)28- PRs have inconsistent descriptions (no template)29- No Code of Conduct signals unclear community standards30- No badges means no at-a-glance project health31- No topics means poor GitHub discoverability32- No Dependabot means dependency vulnerabilities go unnoticed3334---3536## 2. Users3738### 2.1 Primary Users39- Open-source contributors who want to file issues or submit PRs40- Developers evaluating ZERG from the GitHub repo page4142### 2.2 Secondary Users43- Maintainer (rocklambros) — benefits from structured issue reports and consistent PRs4445### 2.3 User Stories46- As a contributor, I want issue templates so that I provide the right information in bug reports47- As a contributor, I want a PR template so that I know what to include in my pull requests48- As a visitor, I want README badges so that I can assess project health at a glance49- As a maintainer, I want Dependabot so that I'm alerted to vulnerable dependencies5051---5253## 3. Functional Requirements5455### 3.1 Core Capabilities5657| ID | Requirement | Priority | Issue | Notes |58|----|-------------|----------|-------|-------|59| FR-001 | Bug report issue template (YAML form) | Must | #185 | Fields: description, repro steps, expected/actual, environment, logs |60| FR-002 | Feature request issue template (YAML form) | Must | #185 | Fields: problem statement, proposed solution, alternatives, context |61| FR-003 | Issue template config.yml | Must | #185 | Disable blank issues, link to Discussions for questions, link to SECURITY.md |62| FR-004 | Pull request template | Must | #186 | Sections: Summary, Changes, Test Plan, Checklist |63| FR-005 | CODE_OF_CONDUCT.md | Must | #186 | Contributor Covenant v2.1 |64| FR-006 | Dependabot config | Must | #187 | pip ecosystem, weekly schedule |65| FR-007 | Enable secret scanning | Must | #187 | Via GitHub API |66| FR-008 | Enable push protection | Should | #187 | Via GitHub API |67| FR-009 | README badges | Must | #188 | PyPI version, Python version, License, CI status |68| FR-010 | GitHub topics | Must | #188 | claude-code, parallel-execution, ai-coding, etc. |69| FR-011 | License compatibility audit | Should | #188 | Verify all deps are MIT/BSD/Apache compatible |70| FR-012 | Update SECURITY.md supported versions | Must | — | Add 0.2.x, reflect current state |7172### 3.2 Inputs73- Issue template YAML specs74- Contributor Covenant v2.1 text75- Dependabot config YAML76- Badge markdown from shields.io7778### 3.3 Outputs79- 6 new files: 3 issue templates, 1 PR template, 1 CoC, 1 Dependabot config80- 2 modified files: README.md (badges), SECURITY.md (versions)81- GitHub API changes: topics, secret scanning, push protection8283### 3.4 Business Rules84- Issue templates use YAML format (renders as forms in GitHub UI)85- Bug report requires: description, repro steps, ZERG version86- Feature request requires: problem statement, proposed solution87- PR template checklist references existing CI requirements88- CoC enforcement contact: use GitHub Security Advisories (no personal email)8990---9192## 4. Non-Functional Requirements9394### 4.1 Performance95N/A — configuration files only, no runtime impact9697### 4.2 Security98- Secret scanning enabled to catch leaked API keys99- Push protection enabled to block commits containing secrets100- Dependabot alerts for dependency vulnerabilities101102### 4.3 Reliability103N/A — static files104105### 4.4 Scalability106N/A — static files107108---109110## 5. Scope111112### 5.1 In Scope113- GitHub issue templates (bug, feature, config)114- PR template115- CODE_OF_CONDUCT.md (Contributor Covenant v2.1)116- Dependabot configuration117- Secret scanning + push protection enablement118- README badges (PyPI, Python, License, CI)119- GitHub repository topics120- License compatibility audit121- SECURITY.md version table update122123### 5.2 Out of Scope124- CodeQL workflow (deferred to Phase 2, #189)125- mypy in CI (deferred to Phase 2, #189)126- mkdocs documentation site (deferred to Phase 2, #190)127- GitHub Discussions setup (already enabled)128- Terminal demo / social preview (deferred to Phase 3, #191)129- Making repo public (separate decision, not part of this spec)130131### 5.3 Assumptions132- Repo stays private during Phase 1 (go-public is a separate step)133- Badges will show "not found" until repo is public — that's fine134- Dependabot alerts are already enabled (confirmed via API)135- Branch protection is already configured from Phase 0136137### 5.4 Constraints138- Must use Contributor Covenant v2.1 (standard, widely recognized)139- Issue templates must use YAML format (not markdown) for form rendering140- All changes must pass existing CI (quality, smoke, test, audit)141142---143144## 6. Dependencies145146### 6.1 Internal Dependencies147| Dependency | Type | Status |148|------------|------|--------|149| Phase 0 (blockers) | Required | Complete |150| Branch protection | Required | Complete (5 checks configured) |151| CONTRIBUTING.md | Reference | Exists |152| SECURITY.md | Reference | Exists (needs version update) |153154### 6.2 External Dependencies155| Dependency | Type | Owner |156|------------|------|-------|157| shields.io | Badge rendering | External service |158| GitHub API | Repo settings | GitHub |159| Contributor Covenant | CoC text | contributorcovenant.org |160161---162163## 7. Acceptance Criteria164165### 7.1 Definition of Done166- [ ] All 6 new files created and committed167- [ ] README badges render (or show expected "not found" while private)168- [ ] GitHub topics set (9 topics)169- [ ] Secret scanning + push protection enabled170- [ ] Dependabot config triggers automated PRs171- [ ] License audit passes (all deps MIT/BSD/Apache compatible)172- [ ] SECURITY.md shows 0.2.x as supported173- [ ] CI passes on PR174- [ ] CHANGELOG.md updated175176### 7.2 Test Scenarios177178| ID | Scenario | Given | When | Then |179|----|----------|-------|------|------|180| TC-001 | Bug report template | Repo has templates | User clicks "New Issue" | Bug report form renders with required fields |181| TC-002 | Feature request template | Repo has templates | User clicks "New Issue" | Feature request form renders |182| TC-003 | Blank issue blocked | config.yml disables blank | User tries blank issue | Redirected to templates or Discussions |183| TC-004 | PR template | Template exists | User opens new PR | Description pre-filled with template |184| TC-005 | Dependabot | Config exists | Dependency has CVE | Dependabot opens alert/PR |185| TC-006 | Badges | Badges in README | User views README | Badges visible with correct links |186187### 7.3 Success Metrics188- All 4 issues (#185-#188) closeable189- Zero new files outside `.github/` and project root190- No runtime code changes191192---193194## 8. Open Questions195196| ID | Question | Owner | Status |197|----|----------|-------|--------|198| Q-001 | Should we enable "require linear history" (squash-only merges)? | maintainer | Resolved: No — allow merge commits |199| Q-002 | What email/contact for CoC enforcement? Use GH Security Advisories link? | maintainer | Resolved: Yes — use GitHub Security Advisories |200201---202203## 9. Approval204205| Role | Name | Date | Signature |206|------|------|------|-----------|207| Product | rocklambros | | PENDING |208209---210211## 10. Documentation212213After implementation:214- CHANGELOG.md updated with Phase 1 entries (ALWAYS required)215- README.md updated with badges216- SECURITY.md version table updated217- CONTRIBUTING.md may need minor link updates (to PR template, CoC)218219---220221## 11. Documentation Impact Analysis222223### 11.1 Files Requiring Documentation Updates224| File | Current State | Required Update | Priority |225|------|--------------|-----------------|----------|226| `CHANGELOG.md` | Has [Unreleased] | Add Phase 1 entries | Must |227| `README.md` | No badges | Add badge row at top | Must |228| `SECURITY.md` | Shows 0.1.x only | Add 0.2.x to supported versions | Must |229| `CONTRIBUTING.md` | Exists, complete | Link to CoC if not already linked | Should |230231### 11.2 Documentation Tasks for Design Phase232- [x] CHANGELOG.md update task (ALWAYS required)233- [x] README.md update (badges)234- [x] SECURITY.md update (version table)235- [ ] CONTRIBUTING.md update (CoC link — check if needed)