Thanks for your interest in improving deglyph. This guide covers the development setup and the checks a change must pass.
Python 3.10 or newer is required.
python3 -m venv .venv
. .venv/bin/activate # Windows: .venv\Scripts\activate
pip install -e ".[dev]" # runtime deps + pytest, ruff, mypy, blackEvery change must pass the same checks CI runs. Run them locally before opening a pull request:
ruff check deglyph scripts tests # lint
black --check deglyph scripts tests # formatting
mypy deglyph # type checking (library)
python scripts/verify.py # tone and comment-style contract
pytest # testsblack is the formatter and its output is the contract; run black . to fix
formatting. scripts/verify.py enforces the comment and prose style described in
CLAUDE.md (no marketing copy, no first-person, ASCII in user-facing docs); keep
it at zero findings.
- Read
CLAUDE.mdfirst. It documents the architecture invariants (the virtual- address model, function identity, thunk resolution, the disassembler arch map) and the behavioral rules for changes. - Type hints on public functions;
from __future__ import annotationsat the top of every module. - The detectors are heuristics. State their limits where results are reported; do not present a detector hit as a verified fact.
- Add a test for new analysis logic. Detector tests assert against hand-assembled
code in
tests/test_detectors.py; loader and disassembler tests may use a host binary and skip when none is present.
- Keep the diff scoped to one change. Note adjacent fixes separately rather than bundling them.
- Update
CHANGELOG.mdunder[Unreleased]. - Update
CLAUDE.mdfor any architectural change a future contributor would otherwise miss.
The package is deglyph on PyPI. Releases publish automatically from
.github/workflows/release.yml when a v* tag is pushed, using PyPI Trusted
Publishing (OIDC), so no API token is stored.
One-time setup (PyPI account owner): on PyPI, add a Trusted Publisher for the
project deglyph pointing at this repository, workflow release.yml, and
environment pypi. For the first ever release, register it as a pending
publisher before pushing the tag.
To cut a release:
- Bump
__version__indeglyph/__init__.pyand move the[Unreleased]notes inCHANGELOG.mdunder the new version. - Tag and push:
git tag vX.Y.Z && git push origin vX.Y.Z. The tag must matchdeglyph.__version__or the workflow fails the version check.