First off, thank you for considering contributing to ZSecTools! Contributions from the community help make this SAP Security & Governance tool better for everyone.
Please take a moment to review these guidelines before submitting code, issue reports, or documentation updates.
By participating in this project, you agree to maintain a respectful, welcoming, and professional environment for all contributors.
Before creating a bug report, please check existing issues to ensure it hasn't already been reported.
When creating a bug report, please use the Bug Report template and include:
- A clear and descriptive title.
- Steps to reproduce the issue.
- Expected vs. actual behavior.
- Environment details (Node.js version, PostgreSQL version, browser).
Feature requests are welcome! Please open an issue using the Feature Request template to discuss your ideas before implementing major changes.
- Fork the Repository: Create your own fork of the project.
- Create a Feature Branch:
git checkout -b feature/my-new-feature
# or
git checkout -b fix/my-bug-fix- Make Your Changes: Follow existing code style patterns (Node.js/Express for backend, React/Vite for frontend).
- Test Thoroughly: Ensure your changes do not break existing SAP database queries or UI components.
- Commit Your Changes: Write clear, descriptive commit messages (e.g.,
feat: add RFC ping to SAP realmsorfix: resolve SQL pagination in SOD results). - Push to GitHub:
git push origin feature/my-new-feature
- Open a Pull Request: Submit your PR against the
mainbranch with a concise description of the changes.
- Clone the Repository:
git clone [https://github.com/va87git/zsectools.git](https://github.com/va87git/zsectools.git)
cd zsectools
- Setup Instructions: Follow the detailed installation and environment configuration steps provided in the main
README.md.
Important Note on Dependencies: If your pull request or feature implementation introduces any new npm packages or external libraries, you must explicitly state them in your Pull Request description and update
package.jsonaccordingly.
- JavaScript / React: Keep components clean and modular. Use functional React components and standard hooks.
- SQL Queries: Ensure parameterized queries are used with
pgto prevent SQL injection risks. - SAP Naming Conventions: Keep standard SAP naming conventions in mind during development (e.g., authorization objects, tables, and transaction codes like
S_SERVICE,AGR_USERS,S_TCODE). - Database Naming Conventions:
- Imported SAP raw tables follow the pattern
sap_raw_[realm]_[table_name]. - Automated background processing tables (such as those generated by "Build additional infos") follow the pattern
yr_[realm]_[short_desc]. - Heavy-data processing features (such as SOD Analysis) use cross-realm tables to prevent data duplication. Maintain this architecture for new data-intensive features to avoid bloating the database.
- Imported SAP raw tables follow the pattern
Thank you for helping build ZSecTools!