A big welcome and thank you for considering contributing to OpenFGA. It's people like you that make it a reality for users in our community.
Reading and following these guidelines will help us make the contribution process easy and effective for everyone involved. It also communicates that you agree to respect the time of the developers managing and developing these open source projects. In return, we will reciprocate that respect by addressing your issue, assessing changes, and helping you finalize your pull requests.
By participating and contributing to this project, you are expected to uphold our Code of Conduct.
Before we can accept your contribution, you will need to sign our Contributor License Agreement (CLA). When you open a pull request for the first time, a bot will guide you through the process.
When contributing to this repository, the first step is to open an issue to discuss the change you wish to make before making it. Before submitting a new issue, please search open and closed issues, and the OpenFGA discussions, to make sure it is not a duplicate.
This is a standard Go module. It requires the Go version declared in go.mod.
Common tasks are available through the Makefile:
make test # run tests with the race detector and coverage
make lint # run golangci-lint
make fmt # format the code
make vet # run go vet
make audit # run govulncheck
make check # run all of the aboveThe repository is organised as two packages:
mapper(module root) — compiles validated mapping configurations into an executableMappingand evaluates events against it. Seedocs/engine.md.language— parses and validates mapping YAML into a canonicalMappingConfig. Seelanguage/README.md.
The user-facing language specification lives in docs/language-spec.md.
Please make sure to follow the existing code style and include tests for your changes. Pull request titles must follow the Conventional Commits format, as it is validated in CI.
Commit message prefixes feed the changelog automatically on release. For user-facing changes where the commit message is too terse, add a BEGIN_COMMIT_OVERRIDE block to the PR body — see RELEASING.md for details.
Please do not open issues for general support or usage questions. Instead, join us in the OpenFGA discussions or the OpenFGA community.
Please do not report security vulnerabilities on the public GitHub issue tracker. The Responsible Disclosure Program details the procedure for disclosing security issues.