Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 10 additions & 7 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -1,14 +1,17 @@
<!--

👋 Thank you for your contribution!
Please make sure to check all of the items below.
👋 Thank you for contributing!

- 🚨 New tools have to be added to `data/tools/` (NOT directly to the `README.md`).
- If you propose to deprecate a tool, you have to provide a reason below.
- More details in the contributors guide, `CONTRIBUTING.md`
New tools belong in `data/tools/`, not directly in `README.md`. Before submitting,
verify that the tool is at least six months old, has at least 20 GitHub stars,
and has more than one human contributor. Bots and automation accounts do not
count, including `[bot]` logins, `claude`, `dependabot`, and `renovate-bot`.
Keep descriptions within 500 characters and leave generated README changes out.
For README text or structure, edit `ci/render/templates/README.md` instead.

-->
If automatic checks cannot verify the criteria, provide evidence for manual
review. If you propose to deprecate a tool, explain why. See `CONTRIBUTING.md`.

* [ ] I have not changed the `README.md` directly.
-->


55 changes: 37 additions & 18 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -1,38 +1,57 @@
# How to add a new tool to the list
# Thank you for contributing

Please feel free to open a pull request if you know of a dynamic analysis tool that
is not mentioned here.
If you're in doubt if a tool is a good fit for the list, **don't open an issue,
but create a pull request right away** because that's easier to handle. Thanks!
:smiley:
We welcome pull requests for dynamic analysis tools that meet the requirements
below. **Please verify all criteria before submitting a tool.** If a tool does
not qualify yet, wait until it does rather than opening a pull request or issue.

### Requirements

Each tool on the list should be
Before submitting, each tool must

- actively maintained (more than one contributor)
- actively used (have **more than 20 stars on Github or similar impact**)
- relatively mature (project exists for at least three months)
- have existed for at least six months
- have at least 20 stars on GitHub
- have more than one human contributor

Bot and automation accounts do not count toward the contributor minimum. The
check excludes GitHub bot accounts, logins ending in `[bot]`, and known automation
accounts such as `claude`, `dependabot`, and `renovate-bot`, even when GitHub lists
them as ordinary users.

These requirements apply to all tools. Meeting the minimum criteria does not
guarantee inclusion.

For new tool entries, the PR checker uses GitHub repository metadata to check
stars, human contributors, and age. Age is measured by subtracting six calendar
months from the check date, not by counting 180 days. Verified unmet criteria
fail the check, but the checker does not automatically close pull requests.
Missing or unavailable metadata, non-GitHub sources, and tools without a source
URL require manual review. Skipped checks do not count as passes; please provide
evidence of age, usage, and human maintenance for reviewers.

### Format

The main `README.md` is just a rendered version of the data. To add a new tool,
please create a file in the `data/tools` directory.
**The main `README.md` is generated from the data. Do not edit it manually.**
Leave generated `README.md` changes out of your pull request, even if you run
`make render` locally. For changes to the README text or structure, edit
`ci/render/templates/README.md` instead.

To add a new tool, create `data/tools/<toolname>.yml`. Check existing entries for
the required fields and format.

- Use a nonblank tool name of at most **50 UTF-8 bytes** (non-ASCII characters
can take more than one byte).
- Make each tool description as precise as possible.
Please limit the description to **500 characters**.
- By default, we assume that the tool is open source.
If a tool is proprietary, add `proprietary: true`.
- Please add as many tags as possible. You can choose from the tags
in `data/tags.yml` If a tool does not match any existing tag, feel
free to add a new tag.
- Add a license. If it is a proprietary tool, use `license: proprietary`.
- Add at least one tag and as many relevant tags as possible from
`data/tags.yml`. If a tool needs a new tag, also add it to `data/tags.yml`.

Finally, create a pull request with all your changes.
You can call `make render` to check for errors before.
This is optional, because it will also be done when creating
a pull request.

# How to mark a tool as unmaintained/deprecated
### How to mark a tool as unmaintained/deprecated

Sometimes a tool becomes unmaintained and there's nothing wrong with that.
After all, a tool can still be very valuable to the community - even without
Expand Down
Loading
Loading