Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 18 additions & 9 deletions Docs/dotnet-foundation.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,14 @@ the claims are checkable rather than asserted. Each row says where the evidence
Application filed 2026-08-01: [dotnet-foundation/projects#545](https://github.com/dotnet-foundation/projects/issues/545).
Transfer model: **Contribution** — the copyright stays with PeopleWorks. Trademarks: **Licensed**.

Last reviewed: 2026-08-01, at version 0.2.1 and desktop 0.2.0.
Last reviewed: 2026-09-16, at version 0.8.1 and desktop 0.8.1. The figures below are dated to that review, not
kept live; the application itself was filed at 0.2.1 and has had no reply.

## Suitability

| Criterion | Status | Evidence |
|---|---|---|
| Built on .NET and/or creates value in the .NET ecosystem | Met | `net10.0` throughout. Ships a library (`SignsOfAI.Core`), a `dotnet tool` (`SignsOfAI.Cli`), an MCP server (`SignsOfAI.Mcp`), a Blazor WebAssembly site and a WPF desktop app. |
| Built on .NET and/or creates value in the .NET ecosystem | Met | `net10.0` throughout. Ships a library (`SignsOfAI.Core`), a `dotnet tool` (`SignsOfAI.Cli`), an MCP server (`SignsOfAI.Mcp`), a Blazor WebAssembly site, a WPF desktop app and a Word task pane, all driven by the same rule packs. |
| Collaborative development philosophy | Met | `CONTRIBUTING.md`. The extension points that matter — the detection rules and the sign catalog — are JSON data files (`src/SignsOfAI.Core/Rules/Packs/rules.{en,es}.json`), not compiled C#, specifically so that a contributor with domain knowledge and no .NET can open a pull request. `Docs/TRANSLATING.md` covers adding a language. |

## Code
Expand All @@ -22,7 +23,7 @@ Last reviewed: 2026-08-01, at version 0.2.1 and desktop 0.2.0.
|---|---|---|
| Source code distributed to the public at no charge | Met | MIT, no paid tier, no gated features. |
| Discoverable and publicly accessible | Met | <https://github.com/peopleworks/SignsofAI> |
| Build script produces artifacts identical to the official ones | Met | Everything the project ships is built by a workflow from the tagged commit on a clean runner, never from a developer machine: `.github/workflows/nuget.yml` for the packages, `desktop-release.yml` for the Windows desktop `.zip`, `deploy-pages.yml` for the site. The desktop release also publishes a SHA-256 sidecar. |
| Build script produces artifacts identical to the official ones | Met | Everything the project ships is built by a workflow from the tagged commit on a clean runner, never from a developer machine: `.github/workflows/nuget.yml` for the packages, `desktop-release.yml` for the Windows installer and `.zip`, both built from the same staging folder, `deploy-pages.yml` for the site. Each desktop artifact gets a published SHA-256 sidecar. |
| Reproducible build settings | Met | `Directory.Build.props`: `Deterministic`, plus `ContinuousIntegrationBuild` under `GITHUB_ACTIONS` so CI builds normalize paths and local builds stay debuggable. |
| Source Link | Met | `Directory.Build.props`: `PublishRepositoryUrl` + `EmbedUntrackedSources`. The GitHub provider is in-box since the .NET 8 SDK, so no `PackageReference` is needed. Verified: the packed `.nuspec` carries `<repository … commit="…">` and the PDB carries the `raw.githubusercontent.com/.../<commit>/*` map. |
| Embedded PDBs or symbol packages | Met | `.snupkg` per package (`IncludeSymbols`, `SymbolPackageFormat=snupkg`), pushed to the NuGet symbol server alongside each `.nupkg`. `nuget.yml` fails the release if any package is missing its symbols. |
Expand All @@ -44,21 +45,29 @@ Last reviewed: 2026-08-01, at version 0.2.1 and desktop 0.2.0.
| Public homepage with status and purpose | Met | <https://peopleworks.github.io/SignsofAI/> — the live application is the homepage. |
| Public issue tracker | Met | GitHub Issues, with templates under `.github/ISSUE_TEMPLATE`. |
| Published security policy | Met | `SECURITY.md` |
| Public communication channel with maintainers | Met | GitHub Issues, and GitHub Discussions — including a *False positives* category, which is where a rule that misfires gets reported. The tool has no server and no telemetry, so a reported false positive is the only signal the project ever receives that a rule is wrong. |
| Public communication channel with maintainers | Met | GitHub Issues, and GitHub Discussions — including a *False positives* category, which is where a rule that misfires gets reported. The tool has no server and no telemetry, so a reported false positive is the only signal that comes *from users*. The rate itself is measured independently: `Docs/CALIBRATION.md` runs the engine over 296 texts written before 2022 and publishes how many it flags — 2 of 296 at the recommended threshold, with the interval. |
| Publicly reviewable and contributable documentation | Met | `README.md`, `Docs/`, and the in-product explanations — every finding the analyzer reports links to the catalog entry that justifies it. |
| Code of Conduct | Met | `CODE_OF_CONDUCT.md` (Contributor Covenant); to be relinked to the .NET Foundation Code of Conduct on onboarding. |
| Account/organization 2FA | Met | Enabled on the PeopleWorks GitHub account, confirmed by the account owner. |

## Known gaps

**Code signing.** Nothing this project ships is signed. The NuGet packages are unsigned, and the
self-contained desktop `.zip` on `desktop-v0.2.0` triggers a SmartScreen warning on first run —
documented in the release notes rather than hidden, but still the roughest edge a new user hits.
desktop app triggers a SmartScreen warning on first run. Since 0.8.1 it ships as a per-user
installer as well as a `.zip`, which removed every other step between a teacher and the app —
unblocking, extracting, keeping the folder together — and left this one: the installer is
unsigned too, and the download page says so rather than implying otherwise.

An Authenticode certificate is the fix, and it is the single concrete resource the project would
ask the Foundation for. The release does publish a SHA-256 so the download can at least be
verified against what this repository built, which is not a substitute for a signature.
ask the Foundation for. The alternatives were checked before asking: Azure Artifact Signing does not
accept free, trial or sponsored subscriptions, and its individual identity validation is limited to
the United States and Canada; a commercial certificate is a recurring cost this project has no
funding for. Either way SmartScreen reputation accrues with download history rather than on the day a
file is signed. Each release publishes a SHA-256, so a download can be verified against what this
repository built — which is not a substitute for a signature.

**One contributor.** 88 commits, all by the project lead, first commit 2026-07-05. The project can
**One contributor.** 245 commits on `main` as of 2026-09-16, all by the project lead, first commit
2026-07-05. The project can
show that it is *built* for contribution — JSON rule packs, a translation guide, issue and PR
templates — but it cannot yet show contributors it has promoted, so the reasonable outcome of an
application is Seed rather than Member.
Loading