Thank you for your interest in contributing to Professional Service Automation (PSA). This project welcomes bug reports, documentation improvements, and pull requests.
- Read
README.mdfor setup and environment variables. - Skim
AGENTS.mdfor the developer contract, module boundaries, and verification gate. - Review
specs/product/mvp-scope.mdto see what is in scope for Phase 1 vs Phase 2.
git clone https://github.com/SafetyMP/Professional-Service-Automation.git
cd Professional-Service-Automation
cp .env.example .env
# Set AUTH_SECRET: openssl rand -base64 32
docker compose up -d
npm install
npm run db:migrate
npm run db:seed
npm run dev -- -p 3005Demo login: organization demo-firm, admin@demo.com / password123. Local dev uses port 3005 (see .env.example AUTH_URL); Docker stack quick start uses port 3000.
- Branch from
main. - Use descriptive branch names, e.g.
fix/invoice-rounding,feat/milestone-billing.
- Domain logic belongs in
lib/<domain>/service.ts. - Cross-domain imports must go through public service files only (see
scripts/check-boundaries.ts). - Match existing TypeScript, React, and Tailwind patterns in the surrounding code.
- Keep diffs focused; avoid unrelated refactors.
When changing billing, profitability, or accounting behavior, update the relevant spec under specs/domain/ and add or adjust unit tests in tests/.
Before opening a pull request, run:
./scripts/verify.shThis runs lint, typecheck, unit tests, module boundary checks, and Prisma validation. CI runs the same gate on every push and pull request.
Individual commands:
| Command | Purpose |
|---|---|
npm run lint |
ESLint |
npm run typecheck |
TypeScript |
npm run test |
Vitest unit tests |
npm run check:boundaries |
Module import boundaries |
- Fill out the pull request template.
- Link related issues when applicable.
- Ensure CI is green.
- Describe user-visible behavior changes and any migration or env var updates.
Reviewers block on P0/P1 issues:
- Auth bypass or session flaws
- Cross-tenant data leaks
- Billing math errors
- Data loss or destructive migrations without a safe path
Use the bug report issue template. Do not file public issues for security vulnerabilities — see SECURITY.md.
Use the feature request issue template. Check the Phase 2 list in specs/product/mvp-scope.md before proposing net-new scope.
This project follows the Code of Conduct. By participating, you agree to uphold it.
Open a GitHub Discussion for questions that are not bugs or feature requests. If Discussions are not enabled on the repository, open a feature request or documentation issue instead.