docs: add the governance and CI-operations files the project never had

The repo had no SECURITY.md, CONTRIBUTING.md, code of conduct, or issue
and PR templates. For a client that handles Jellyfin credentials and
ships signed binaries, the missing one that actually matters is
SECURITY.md: there was no stated way to report a vulnerability
privately, so the only available channel was the public tracker.

CONTRIBUTING.md documents the gates as they now stand, including the
three ratchets and which direction each is allowed to move, and the two
rules that surprise people: bug fixes start with a failing test, and
Jellyfin's taxonomy stays in Rust.

The bug template asks the three playback questions -- streaming or
downloaded, transcoding or direct, music or video -- because those
answers decide which of several very different code paths a report is
about, and reconstructing them over several round trips is most of the
cost of a playback bug report.

docs/build/ci-operations.md is the missing operations manual: how to
change the builder image and in what order (image pushed before the
workflow that names it, or CI breaks), why tags are dated rather than
:latest or per-SHA, what each secret is for, and what losing the updater
private key would mean -- installed desktop clients only accept payloads
signed by the key matching the public key they shipped with, so losing it
means everyone reinstalls by hand.

Disk exhaustion on the runner is documented as a manual check rather than
a scheduled job. A daily job would occupy the only slot on a single-slot
runner and pull the whole builder image to run `df` -- and `df` inside a
container does not reliably describe the host's disk, so it would spend
real build capacity reporting a number that might be wrong. What the doc
records instead is the part that is actually hard to rediscover: the
symptoms (cargo dying mid-link, docker refusing to pull, actions/cache
quietly not saving) and that `docker volume prune` needs `-a` to touch
named volumes, which is how it filled up unnoticed.

Two things in these docs are stated plainly because they are true and
were not written down anywhere: without branch protection every gate in
the pipeline is advisory, and the Gitea instance -- canonical remote,
signing secrets, registry, runner -- is not backed up by anything in this
repository.
This commit is contained in:
2026-08-21 18:45:40 +02:00
parent 3211c96ecf
commit 6897b290ed
8 changed files with 568 additions and 0 deletions
+103
View File
@@ -0,0 +1,103 @@
name: Bug report
about: Something behaves incorrectly
title: ""
labels: ["bug"]
body:
- type: markdown
attributes:
value: |
Security vulnerabilities do **not** go here — see
[SECURITY.md](../../SECURITY.md).
- type: textarea
id: what-happened
attributes:
label: What happened
description: What you did, what you expected, and what you got instead.
placeholder: |
1. Opened an album from the Music library
2. Tapped the third track
3. Playback started from the first track instead
validations:
required: true
- type: input
id: version
attributes:
label: JellyTau version
description: Settings scrolls to the bottom, or the filename you installed.
placeholder: "0.9.1"
validations:
required: true
- type: dropdown
id: platform
attributes:
label: Platform
options:
- Linux (AppImage)
- Linux (deb)
- Linux (rpm)
- Linux (Arch package)
- Windows
- Android
validations:
required: true
- type: markdown
attributes:
value: |
### Playback questions
If this involves playback, these three answers decide which of several
very different code paths you were on. "I don't know" is a fine answer.
- type: dropdown
id: source
attributes:
label: Was the media streaming or downloaded?
options:
- Streaming from the server
- Downloaded for offline use
- Not playback-related
validations:
required: true
- type: dropdown
id: transcode
attributes:
label: Was the server transcoding?
description: Jellyfin's dashboard shows this while something is playing.
options:
- Direct play
- Transcoding
- Don't know
- Not playback-related
- type: dropdown
id: kind
attributes:
label: Music or video?
options:
- Music
- Video (movie)
- Video (TV episode)
- Not playback-related
- type: textarea
id: logs
attributes:
label: Logs
description: |
Android: `adb logcat | grep -i jellytau`.
Linux: run from a terminal, or `RUST_LOG=debug jellytau` for more.
In the app, `localStorage.setItem("jellytau:logLevel","debug")` in the
webview console turns the frontend up too.
render: shell
- type: textarea
id: server
attributes:
label: Jellyfin server
description: Version, and anything unusual about the library layout.
placeholder: "10.9.11, series stored without season folders"
+37
View File
@@ -0,0 +1,37 @@
name: Feature request
about: Suggest something JellyTau should do
title: ""
labels: ["enhancement"]
body:
- type: textarea
id: problem
attributes:
label: What are you trying to do?
description: |
The situation, not the solution. "I listen to albums in a fixed order and
lose my place when I switch devices" tells us more than "add a sync
button", and often has a better answer than the one you had in mind.
validations:
required: true
- type: textarea
id: proposal
attributes:
label: What would you like it to do?
validations:
required: true
- type: dropdown
id: platform
attributes:
label: Which platforms does this matter on?
multiple: true
options:
- Linux
- Windows
- Android
- type: textarea
id: alternatives
attributes:
label: Anything you have tried, or how other clients handle it