Contributing
BackupProof is open source under the MIT license. Bug reports, fixes, documentation and new import formats are all welcome.
Ways to help
- Report a bug in GitHub issues with your version, system and the steps to reproduce it.
- Report a security problem privately, as described on the Security page.
- Improve the wording. If something in the dashboard or these docs confused you, that’s a bug too.
- Send a pull request for a fix or feature. For anything large, open an issue first so we can agree on the approach.
Set up
You need Go 1.27 or later. Optionally install restic, kopia, rclone, gpg, openssl and age to run the import tests that use them (tests skip when a tool is missing), Docker to try database restore tests, and golangci-lint v2.
git clone https://github.com/chmuzamil/BackupProof.git
cd BackupProof
go build -o bin/backupproof ./cmd/backupproof
go test ./...
./bin/backupproof server --data ./backupproof-data --listen 127.0.0.1:8420
Open http://127.0.0.1:8420 and create the admin account. The built-in server connects automatically.
Find your way around
| Folder | What’s there |
|---|---|
cmd/backupproof | The single program: dashboard, agent and command-line tool. |
internal/repo, engine, chunker, crypto, snapshot | Storage format, backup, restore and cleanup, chunking, encryption, the Merkle tree. |
internal/source | What gets backed up: files, databases, commands. |
internal/drill | Restore tests and their sandboxes. |
internal/proof | Signed statements, the ledger, timestamps and bundles. |
internal/importer | Converting existing backups. |
internal/server | Dashboard API, scheduler, alerts and proof reports. web/ holds the dashboard (plain JavaScript, no build step). |
internal/agent, protocol | The outbound-only agent and how it talks to the dashboard. |
internal/e2e | End-to-end tests of the dashboard and agent together. |
Before a pull request
gofmt -l . # must print nothing
go vet ./...
go test -race ./... # plain go test on Windows
golangci-lint run ./...
node --check internal/server/web/app.js
CI runs the same checks on Linux and Windows, plus govulncheck.
Guidelines
- Security first. Changes to restore paths, agent authentication, roles or proofs need a test that tries the attack and shows it fails.
- Plain language in the dashboard. Use the existing words (“Restore test”, “Backup storage”, “Servers”) and keep technical details behind “Show technical details”.
- Keep the dashboard CSP-clean. No inline scripts or styles, no third-party assets, and never put server data into
innerHTML. - Don’t change storage or proof formats without a version bump and a migration note in the changelog.
- Commit messages in the imperative (“Add Kopia import”), explaining why in the body when it isn’t obvious.