Framework-agnostic PII anonymization extracted from Mobiletic's chatbot. Pluggable LLM detection + configurable regex fallback, deterministic coreference, and streaming-safe de-anonymization. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
38 lines
1.4 KiB
Markdown
38 lines
1.4 KiB
Markdown
# Contributing to @mobiletic/anonymizer
|
|
|
|
Thanks for your interest in improving this project! Contributions of all kinds are welcome — bug reports,
|
|
new pattern presets, additional LLM providers, docs, and tests.
|
|
|
|
## Getting started
|
|
|
|
```bash
|
|
git clone https://github.com/mobiletic/anonymizer.git
|
|
cd anonymizer
|
|
npm install
|
|
npm test # run the test suite (vitest)
|
|
npm run typecheck # tsc --noEmit
|
|
npm run build # tsup → dist/ (ESM + CJS + types)
|
|
```
|
|
|
|
## Guidelines
|
|
|
|
- **Tests first.** Every behavior change needs a test. The anonymization core is privacy-critical — we
|
|
keep coverage tight, especially around coreference, de-collision, and streaming.
|
|
- **No runtime dependencies.** The core must stay dependency-free. New providers should rely only on
|
|
platform APIs (e.g. `fetch`).
|
|
- **Keep it framework-agnostic.** No framework-specific code (NestJS, Express, React, …) in the package.
|
|
- **Patterns use the global flag.** Any `PatternDef.re` must be a global (`/…/g`) regex.
|
|
- **Conventional commits** are appreciated (`feat:`, `fix:`, `docs:`, `test:`, `chore:`).
|
|
|
|
## Reporting security issues
|
|
|
|
Please do **not** open public issues for vulnerabilities (e.g. a PII-leak path). Email
|
|
`security@mobiletic.com` instead.
|
|
|
|
## Pull requests
|
|
|
|
1. Fork and branch from `main`.
|
|
2. Add tests and update docs.
|
|
3. Ensure `npm test`, `npm run typecheck`, and `npm run build` pass.
|
|
4. Open the PR with a clear description of the change and its motivation.
|