Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/spec-issue.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,4 +34,4 @@ labels: specification
- [ ] 影响实现行为(需同步更新样例、产品接入或后续参考实现)
- [ ] 破坏性变更(影响已有实现的兼容性)

ACT 2.1 已定稿。新增规范行为不会直接写入 ACT 2.1,应按治理流程进入未来版本和公开决策记录。
ACT 2.1 已定稿。新增规范行为不会直接写入 ACT 2.1,应面向未来协议版本提出。
13 changes: 12 additions & 1 deletion .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,8 +31,19 @@

## 破坏性变更或未来版本提案

<!-- 如适用,请说明迁移方案、安全影响和对应公开决策记录。 -->
<!-- 如适用,请说明目标协议版本、迁移方案和安全影响。 -->

## 测试

<!-- 说明如何验证本次变更,并附上 ./tools/verify.sh 或相称检查的结果。 -->

## AI 辅助使用

<!--
如 AI 实际参与了代码生成、翻译、测试生成、资料整理或评审,请说明使用范围以及人工核验方式。
仅使用普通补全且未形成实质内容时可填写“无实质性 AI 生成内容”。
-->

- [ ] 我已人工检查 AI 生成或修改的内容,并对提交结果负责
- [ ] 我已核对其中涉及的协议语义、产品事实、链接和引用
- [ ] 我没有向未经批准的 AI 服务提供密钥、支付凭证、个人信息或未脱敏证据
13 changes: 9 additions & 4 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,11 @@
# Changelog

本文件记录各公开发布版本的变更。版本标识与发布日期与 [`release-manifest.json`](release-manifest.json) 及 [`governance/releases/`](governance/releases/) 中的发布记录保持一致;规范定版日期以 [`governance/decisions/`](governance/decisions/) 的决策记录为准。规范语义变更遵循 [GOVERNANCE.md](GOVERNANCE.md):ACT 2.1 已定版,非勘误性质的规范性变更须以新的协议版本发布。
本文件记录各公开发布版本的变更。版本标识、发布日期、规范定版日期和发布内容以 [`release-manifest.json`](release-manifest.json) 为准。ACT 2.1 已定版,非勘误性质的规范性变更须以新的协议版本发布。

## Repository maintenance — 2026-08-27

- 将 TSD-CRD 参考实现的实现基线、架构、快速开始、安全模型和可选扩展说明集中到 `integrations/tsd-crd/`,可运行代码继续保留在 `code/samples/tsd-crd-reference/`。
- 明确 TSD-CRD 是 ACT 2.1 的规范性协议子篇;`reference-v1` 机器 Profile、Reference Implementation 及其实现指南不增加或替代 ACT 2.1 协议要求。

## Repository update — 2026-08-24

Expand All @@ -11,13 +16,13 @@

## ACT 2.1 — 2026-08-14

- 发布 ADD、CID、PSD、TSD 四域规范,以及独立 A402 接入协议和 L1/L2/L3 场景指南。
- 发布协议概览及 ADD、CID、PSD、TSD 四域规范;A402 和 L1/L2/L3 均由支付服务域正文定义,提取文档仅作为非规范性便捷指南。
- 将 A402 JSON Schema、fixtures 与测试断言作为非规范性机器实现产物发布。
- 提供通用本地 A402 样例、支付宝买卖方接入示例、沙箱验证指引和机器支付 Demo。
- 采用 `docs/`、`code/`、`integrations/` 三层结构,明确协议、通用工程产物与产品实现边界。
- 公开发布树仅包含 ACT 2.1 规范、实现辅助产物、样例、产品接入和必要治理记录,不包含 ACT 2.0 或内部治理资料。
- 公开发布树仅包含 ACT 2.1 规范、实现辅助产物、样例、产品接入和必要项目政策,不包含 ACT 2.0 或内部过程资料。
- 收口 ISR 术语、CID–PSD 机器契约边界和公共协议入口的版本权威说明。
- 支付宝买方预检对齐官网 Node.js 22+ / npm 10+ 要求,并固定仓库维护的 ACT–Alipay 集成映射标识。
- 卖方示例补充有效账单复用、Proof 拒绝后的先对账恢复规则和交易号最小披露,避免重复支付或返回过期账单。
- Demo 明确区分引导演示、官方沙箱事件与证据回放,并移除活动过程材料。
- Demo 收敛为不连接真实支付的 L1/L2/L3 引导演示;官方沙箱仅保留为支付宝集成的外部验证环境。
- 将仓库质量与发布程序收敛到 `tools/` 主架构,统一提供 `./tools/verify.sh` 验证入口,并明确工具不定义协议语义。
95 changes: 95 additions & 0 deletions CODE_OF_CONDUCT.en.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,95 @@
# Contributor Covenant Code of Conduct

[简体中文](CODE_OF_CONDUCT.md) | English

## Our Pledge

As members, contributors, and maintainers of the ACT Protocol community, we are committed to providing an open, inclusive, professional, and respectful environment. We pledge to make participation in our project and community a harassment-free experience for everyone, regardless of age, body size, disability, ethnicity, gender identity and expression, level of experience, education, socioeconomic status, nationality, personal appearance, race, religion, or sexual orientation.

Because ACT Protocol relates to payments and financial services, we place particular emphasis on the following principles:

- **Integrity and transparency:** Be honest and open in discussions about specification design and implementation.
- **Safety first:** Put fund safety and user privacy first.
- **Professional collaboration:** Approach every technical discussion professionally and responsibly.

## Our Standards

Examples of behavior that contributes to a positive environment include:

- Using welcoming and inclusive language.
- Respecting differing viewpoints and experiences, especially when evaluating technical approaches.
- Gracefully accepting constructive criticism and focusing on the technical issue rather than the individual.
- Focusing on what is best for the protocol ecosystem.
- Showing empathy toward other community members.
- Reporting security issues responsibly through the security disclosure process.
- Providing specific and actionable feedback when reviewing code and specifications.

Examples of unacceptable behavior include:

- The use of sexualized language or imagery, and sexual attention or advances of any kind.
- Trolling, insulting or derogatory comments, and personal or political attacks.
- Public or private harassment.
- Publishing another person's private information, such as a physical or email address, without explicit permission.
- Other conduct that could reasonably be considered inappropriate in a professional setting.
- Knowingly spreading misleading information about protocol security.
- Retaliating against or threatening contributors who report security vulnerabilities.

## Enforcement Responsibilities

Project maintainers are responsible for:

1. Clarifying the standards of acceptable behavior.
2. Taking appropriate and fair corrective action in response to unacceptable behavior.
3. Maintaining the order and quality of technical discussions.
4. Protecting contributors who responsibly disclose security issues.

Maintainers have the right and responsibility to remove, edit, or reject comments, commits, code, wiki edits, issues, and other contributions that do not align with this Code of Conduct. They may temporarily or permanently ban contributors whose behavior is rude, threatening, offensive, or harmful.

## Scope

This Code of Conduct applies to:

- Project spaces and all public communication channels, including GitHub Issues, pull requests, and Discussions.
- Project-related technical meetings and events.
- One-to-one communications when representing the project.
- Activity on official social media accounts.
- Conduct outside project repositories or community spaces when it is related to the project.

## Enforcement

### Reporting

Use the reporting and blocking tools provided by the hosting platform for Code of Conduct incidents. Do not disclose the identities, contact details, conversation records, or other sensitive information of affected people in a public Issue, Discussion, or pull request.

Security vulnerabilities must not be reported through this channel. Follow the [Security Policy](SECURITY.md) and submit them to AntSRC.

### Handling Process

1. **Receipt:** The maintainer confirms the report after it has been received and initially reviewed.
2. **Assessment:** The urgency and validity of the report are assessed.
3. **Investigation:** The maintainer may contact relevant parties and collect additional information when necessary.
4. **Decision:** Appropriate action is selected based on the circumstances.
5. **Follow-up:** The reporter is informed of the outcome where possible, subject to privacy protections.

### Corrective Actions

Depending on the severity of the violation, actions may include:

- A verbal or written warning.
- Temporary restriction from project participation, such as a commenting restriction.
- Permanent restriction from project participation.
- Legal action in cases involving malicious security-related conduct, where appropriate.

## Attribution

This Code of Conduct is adapted from the [Contributor Covenant](https://www.contributor-covenant.org), version 3.0, with modifications for ACT Protocol.

References:

- [Contributor Covenant v3.0](https://www.contributor-covenant.org/version/3/0/code_of_conduct/)
- [Microsoft Open Source Code of Conduct](https://opensource.microsoft.com/codeofconduct/)
- [CNCF Code of Conduct](https://github.com/cncf/foundation/blob/main/code-of-conduct.md)

---

*Last updated: August 2026*
4 changes: 3 additions & 1 deletion CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# 贡献者公约行为准则

[English](CODE_OF_CONDUCT.en.md) | 简体中文

## 我们的承诺

作为 ACT Protocol 社区的成员、贡献者和维护者,我们致力于打造一个开放、包容、专业且相互尊重的协作环境。我们承诺,参与我们的项目和社区将为每个人提供无骚扰的体验,无论其年龄、体型、残疾、种族、性别认同和表达、经验水平、教育程度、社会经济地位、国籍、外貌、种族、宗教或性取向如何。
Expand Down Expand Up @@ -57,7 +59,7 @@

### 报告渠道

请通过 ACT 项目公开联系邮箱 `alipay.ai@service.alipay.com` 私密提交,并在邮件主题中注明“ACT Code of Conduct”。请不要通过公开 Issue、Discussion 或 PR 披露受影响人员身份、联系方式、对话记录或其他敏感细节。紧急的平台滥用行为也可以同时使用代码托管平台自身的举报和屏蔽能力。
行为准则事件请使用代码托管平台提供的举报和屏蔽能力。请不要通过公开 Issue、Discussion 或 PR 披露受影响人员身份、联系方式、对话记录或其他敏感细节。

安全漏洞不使用本渠道,应按[安全披露政策](SECURITY.md)提交至 AntSRC。

Expand Down
36 changes: 36 additions & 0 deletions CONTRIBUTING.en.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# Contributing to ACT Protocol

[简体中文](CONTRIBUTING.md) | English

Thank you for contributing to ACT Protocol. Read the [Code of Conduct](CODE_OF_CONDUCT.en.md) and existing issues before starting.

## Choose the Right Entry Point

- Specification errata, clarifications, or proposals for a future version: [Specification issue template](.github/ISSUE_TEMPLATE/spec-issue.md)
- Samples, Schema, product integrations, demos, or tooling: [Implementation issue template](.github/ISSUE_TEMPLATE/implementation-issue.md)
- A change ready for submission: [Pull request template](.github/PULL_REQUEST_TEMPLATE.md)
- Security vulnerabilities: do not open a public issue; follow the private process in the [Security Policy](SECURITY.md)

## Submit a Change

1. Open an issue before proposing protocol semantics, new behavior, or a breaking change. Security vulnerabilities must use the private channel specified in [SECURITY.md](SECURITY.md).
2. Keep each pull request focused and identify whether it changes the protocol, machine-readable artifacts, a product integration, or documentation.
3. Add tests appropriate to the change and run `./tools/verify.sh`.
4. Explain compatibility and security impact in the pull request.

ACT 2.1 is final. Typographical corrections and clarifications that do not change meaning may be applied. New normative behavior must target a future protocol version. JSON Schema, integrations, and examples must not add requirements that are absent from the specification.

Product integrations must cite current official product sources, keep credentials out of the repository, and avoid presenting local tests as real sandbox evidence.

Contributors confirm that they have the right to submit their material. Accepted contributions use the license assigned to the relevant file or directory by [LICENSE](LICENSE). No additional CLA or DCO sign-off is currently required.

## AI-Assisted Contributions and Reviews

AI tools may be used to assist with code, specification text, documentation, tests, and reviews. They do not replace the judgment or responsibility of contributors and reviewers.

- Disclose the areas in which AI materially contributed to the pull request, such as code generation, translation, test generation, research organization, or review suggestions. Routine completion that did not produce material content does not need to be disclosed.
- Before submission, personally review generated content, run the appropriate tests, and take responsibility for accuracy, security, license compliance, and the final result.
- Do not provide secrets, tokens, payment credentials, personal information, unsanitized evidence, or other sensitive material to an AI service that has not been approved for that data.
- Do not directly rely on AI-generated protocol semantics, product APIs, error codes, links, citations, or compatibility conclusions. Verify each of them against the ACT specification, official product sources, and actual test results.
- Treat AI review output as advisory. Reviewers should pay particular attention to fabricated facts, missed edge cases, inadequate tests, insecure code, incorrect translations, and attempts to let machine artifacts or product behavior redefine protocol semantics.
- The pull request author remains responsible for the submitted content. The project maintainer makes the final acceptance decision.
43 changes: 28 additions & 15 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -1,23 +1,36 @@
# Contributing to ACT Protocol
# 贡献指南

Thank you for contributing. Read the [Code of Conduct](CODE_OF_CONDUCT.md), [governance rules](GOVERNANCE.md), and existing issues before starting.
[English](CONTRIBUTING.en.md) | 简体中文

## Repository map
感谢你参与 ACT Protocol。开始前请阅读[行为准则](CODE_OF_CONDUCT.md)并查看现有 Issue。

- `docs/`: ACT 2.1 specification, flows and explanatory material.
- `code/`: machine artifacts, product-neutral samples and demos.
- `integrations/`: provider-specific integrations, including Alipay.
- `tools/`: active repository quality and release tooling; it does not define protocol semantics.
## 选择入口

## Workflow
- 协议勘误、澄清或未来版本建议:[规范 Issue 模板](.github/ISSUE_TEMPLATE/spec-issue.md)
- 样例、Schema、产品接入、Demo 或工具问题:[实现 Issue 模板](.github/ISSUE_TEMPLATE/implementation-issue.md)
- 准备提交变更:[Pull Request 模板](.github/PULL_REQUEST_TEMPLATE.md)
- 安全漏洞:不要创建公开 Issue,请按[安全政策](SECURITY.md)私密提交

1. Open an issue for protocol semantics, new behavior or a breaking change. Security vulnerabilities must use the private channel in [SECURITY.md](SECURITY.md).
2. Keep each pull request focused and identify whether it changes protocol, implementation artifacts, a product integration or documentation.
3. Add tests appropriate to the change and run `./tools/verify.sh`.
4. Explain compatibility, security and source impact in the pull request.
## 提交变更

ACT 2.1 is final. Typographical fixes and clarifications may update it without changing meaning; new normative behavior requires a future version and an accepted public decision. JSON Schema and examples must not silently expand normative requirements.
1. 涉及协议语义、新行为或破坏性变更时,请先创建 Issue。安全漏洞必须通过 [SECURITY.md](SECURITY.md) 指定的私密渠道提交。
2. 每个 Pull Request 应聚焦单一主题,并说明变更属于协议、机器产物、产品接入还是文档。
3. 根据变更补充相应测试,并运行 `./tools/verify.sh`。
4. 在 Pull Request 中说明兼容性和安全影响。

Product integrations must cite current official product sources, keep credentials out of the repository and avoid presenting local tests as real sandbox evidence.
ACT 2.1 已定稿。文字勘误和不改变含义的澄清可以更新;新增规范性行为必须面向未来协议版本。JSON Schema、产品接入和示例不得增加协议正文中不存在的要求。

Contributors confirm they have the right to submit their material. Accepted contributions use the license assigned to the relevant file or directory by [LICENSE](LICENSE). No additional CLA or DCO sign-off is currently required.
产品接入必须引用当前有效的官方产品来源,不得向仓库提交凭证,也不得把本地测试表述为真实沙箱证据。

贡献者应确认有权提交相关内容。被接受的贡献适用 [LICENSE](LICENSE) 对相应文件或目录规定的许可证。目前不要求额外签署 CLA 或进行 DCO sign-off。

## AI 辅助贡献与评审

可以使用 AI 工具辅助编写代码、规范文本、文档、测试和评审,但 AI 不能替代贡献者或评审者的判断与责任。

- 在 Pull Request 中说明 AI 实际参与的范围,例如代码生成、翻译、测试生成、资料整理或评审建议;仅使用普通补全且未形成实质内容时无需披露。
- 提交前由贡献者本人检查生成内容,运行相应测试,并对准确性、安全性、许可证合规性和最终结果负责。
- 不得将密钥、Token、支付凭证、个人信息、未脱敏证据或其他敏感资料提交给未经批准的 AI 服务。
- 不得直接采用 AI 生成的协议语义、产品 API、错误码、链接、引用或兼容性结论;必须与 ACT 规范、官方产品来源和实际测试结果逐项核对。
- AI 评审结果仅作为辅助意见。评审者应重点检查虚构事实、遗漏边界条件、不充分测试、不安全代码、错误翻译,以及机器产物或产品行为反向定义协议语义的问题。
- Pull Request 的作者仍对提交内容负责,最终接受决定由项目维护者作出。
27 changes: 0 additions & 27 deletions GOVERNANCE.md

This file was deleted.

Loading
Loading