Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# Code of Conduct

## Our Standards

- Be respectful, direct, and evidence-oriented in issues, pull requests, reviews, and discussions.
- Assume technical disagreement is about the work. Keep feedback specific to code, docs, data, evidence, reproducibility, or operational risk.
- Avoid harassment, insults, discriminatory language, personal attacks, and repeated off-topic comments.
- Do not pressure maintainers or contributors to disclose private account details, credentials, trading records, unpublished data, or personal information.

## Project Scope

This repository builds artifact-first market signal sources for QuantStrategyLab strategy platforms: it reads market data, computes deterministic derived indicators, and publishes hash-pinned signal bundles and contracts for downstream consumers. Contributions should keep claims about signal quality and coverage conservative and verifiable, separate research evidence from runtime/platform guarantees, and avoid presenting indicator outputs as investment advice. Discussions touching provider data licensing, artifact provenance, or downstream platform consumption should stay measured, reproducible, and evidence-based rather than speculative.

## Reporting and Enforcement

Report conduct concerns to the maintainer on GitHub: `@Pigbibi`. Maintainers may edit or remove comments, close issues or pull requests, restrict participation, or take other reasonable steps to protect contributors and project integrity.
28 changes: 28 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
# Contributing

Thanks for contributing to `MarketSignalSources`.

## Ground Rules

- Prefer small, low-risk pull requests.
- Keep refactors separate from behavior changes.
- Add or update tests when changing runtime behavior.
- Do not use deployment or scheduled workflows as a substitute for local verification.
- This repository only produces signal artifacts and contract validators; it does not submit orders, hold broker credentials, or mutate platform runtime settings. Changes that would add any of those belong in a different repository.
- Keep artifact schemas (`market_signal_bundle.v1`, `market_signal_quality_report.v1`, `market_signal_consumer_contracts.v1`, and related manifests) backward compatible, or call out the break explicitly and update all affected validators in the same pull request.

## Branching and Pull Requests

- Create a topic branch for each change.
- Open a pull request with a short summary and a concrete test plan.
- Wait for CI to pass before merging.

## Local Verification

Run the main verification commands before opening a pull request:

```bash
python -m pip install -e . pytest 'ruff==0.15.22' build
ruff check .
python -m pytest tests -q
```
3 changes: 1 addition & 2 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# MarketSignalSources

Artifact-first market signal source builders for QuantStrategyLab strategy platforms.

## QSL architecture role

Expand All @@ -9,8 +10,6 @@
- **Consumes**: public/market inputs and downstream strategy consumers.
- **Must not**: submit orders or mutate platform runtime settings.

Artifact-first market signal source builders for QuantStrategyLab strategy platforms.

## Installation

This package is intended to be consumed directly from GitHub by strategy and
Expand Down
3 changes: 1 addition & 2 deletions README.zh-CN.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# MarketSignalSources

QuantStrategyLab 策略平台的市场信号源构建工具包,采用 artifact-first 设计。

## QSL 架构角色

Expand All @@ -9,8 +10,6 @@
- **消费对象**:公开/市场输入和下游策略消费者。
- **禁止事项**:下单或修改平台 runtime settings。

QuantStrategyLab 策略平台的市场信号源构建工具包,采用 artifact-first 设计。

## 安装

```bash
Expand Down
22 changes: 22 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Security Policy

Thanks for helping keep `MarketSignalSources` safe.

This repository builds and publishes market signal artifacts consumed by QuantStrategyLab strategy and platform repositories. It does not hold broker credentials or submit orders, but published artifacts and manifests can still affect what downstream platforms inject into live strategies. Please do **not** open a public issue for vulnerabilities involving provider credentials, artifact integrity (e.g. a way to forge or tamper with a signal bundle's hash/provenance so it passes validation), or secret material.

## Reporting a Vulnerability

- Contact the maintainer directly at GitHub: `@Pigbibi`.
- Include the repository name, affected commit or branch, environment details, and exact reproduction steps.

## Secret and Credential Exposure

If you suspect provider API keys, tokens, or other credentials were exposed in this repository (for example in a committed artifact, fixture, or log):

1. Rotate the exposed secrets immediately.
2. Pause any scheduled publication job that depends on the exposed credential.
3. Share only the minimum evidence needed to reproduce the issue.

## Scope Notes

Security fixes should stay minimal and focused. Please avoid bundling unrelated refactors with a security report or patch.
Loading