Thank you for your interest in contributing to LLX! This document provides guidelines and best practices for contributors.
- Getting Started
- Development Setup
- Security Guidelines
- Code Style
- Testing
- Submitting Changes
- GitHub Push Protection
- Fork the repository
- Clone your fork:
git clone https://github.com/YOUR_USERNAME/llx.git - Set up the development environment (see below)
- Create a feature branch:
git checkout -b feature/your-feature-name
python -m venv .venv source .venv/bin/activate # On Windows: .venv\Scripts\activate
pip install -e ".[dev,prellm-full]"
pre-commit install
### ⚠️ Critical: Avoiding GitHub Push Protection Blocks
When adding examples or test data that contain "fake secrets" (API keys, tokens, passwords), follow these rules to prevent GitHub from blocking your push:
# ❌ BAD - Looks like a real secret
STRIPE_KEY = "sk_live_EXAMPLE_DUMMY_KEY_NOT_REAL"
STRIPE_KEY = "sk_live_EXAMPLE_DUMMY_KEY_NOT_REAL"
# ✅ GOOD - Clearly marked as placeholder
STRIPE_KEY = "sk_live_EXAMPLE_DUMMY_KEY_NOT_REAL"
STRIPE_KEY = "sk_live_EXAMPLE_DUMMY_KEY_NOT_REAL"
STRIPE_KEY = "<YOUR_STRIPE_LIVE_KEY_HERE>"
STRIPE_KEY = "sk_live_EXAMPLE_DUMMY_KEY_NOT_REAL" # GitHub allows this pattern
STRIPE_KEY = "sk_live_EXAMPLE_DUMMY_KEY_NOT_REAL" # This is a dummy key for documentation
#### 3. Use Safe Patterns for Common Secrets
| Secret Type | ❌ Bad Pattern | ✅ Safe Pattern |
|-------------|---------------|-----------------|
| Stripe | `sk_live_EXAMPLE_DUMMY_KEY_NOT_REAL[a-zA-Z0-9]{24,}` | `sk_live_EXAMPLE_DUMMY_KEY_NOT_REAL*` or `<...>` |
| GitHub Token | `ghp_[a-zA-Z0-9]{36}` | `ghp_EXAMPLE_TOKEN` |
| AWS Access Key | `AKIA[0-9A-Z]{16}` | `AKIAEXAMPLE12345678` |
| Generic API Key | `[a-zA-Z0-9]{32,64}` | `EXAMPLE_API_KEY_*` |
#### 4. Pre-Push Verification
Before pushing, run:
```bash
# Check for suspicious patterns
grep -rE "(sk_live_EXAMPLE_DUMMY_KEY_NOT_REAL|ghp_|AKIA[0-9A-Z]{16})" examples/ tests/ docs/ \
--include="*.py" --include="*.md" --include="*.yaml"
# If you have git-secrets installed
git secrets --scan
- Never commit real
.envfiles - Use
OPENROUTER_API_KEY: dummy-key-for-ciin CI configs - Store real secrets in environment variables only
- Use
~/.pypircfor PyPI credentials (never commit them)
We use:
- ruff for linting and formatting
- mypy for type checking
- pytest for testing
Run before committing:
ruff check . --fix
ruff format .
mypy llx/All contributions should include tests:
# Run with coverage
pytest --cov=llx --cov-report=html
# Run specific test file
pytest tests/test_privacy.py -vIf GitHub blocks your push with "Push Protection" error:
-
Identify the problem:
git push origin main 2>&1 | grep -A10 "secret"
-
Fix the files (see docs/GITHUB_PUSH_PROTECTION.md for detailed steps)
-
Amend the commit:
git add -A git commit --amend --no-edit git push origin main
-
If still blocked, see docs/GITHUB_PUSH_PROTECTION.md
- Ensure all tests pass:
pytest - Run
pyqual runlocally to verify the full pipeline - Update documentation if needed
- Create a Pull Request with clear description
- Open an issue for bugs or feature requests
- See docs/GITHUB_PUSH_PROTECTION.md for push protection help
- Check existing examples in
examples/for patterns
Thank you for contributing!