Thanks for your interest in improving Superagent Security Bot for GitHub.
-
Install Node.js 22.18 or newer.
-
Install dependencies:
npm install
-
Copy
.env.exampleto.envand fill in the required values for local development. -
Start the development server:
npm run dev
Run the core checks locally:
npm run typecheck
npm testWhen changing PR scanning, contributor scoring, GitHub webhook handling, or security policy behavior, include focused tests that cover the new behavior and any relevant abuse case.
- Keep changes focused and easy to review.
- Explain the security impact of behavior changes.
- Avoid committing secrets, installation tokens, private keys, or local
.envfiles. - Update documentation when behavior, configuration, or setup steps change.
If you believe you have found a security issue, do not open a public issue with exploit details. Contact the maintainers privately with a description of the impact, affected code paths, and reproduction steps.