Contributing
erxes accepts code, documentation, tests, translations, bug reports, and security reports.
Ways to contribute
| Contribution | Where it goes | Start here |
|---|---|---|
| Bug report or feature request | GitHub Issues | Search first. Include the erxes version (root package.json version), the affected plugin, reproduction steps, and expected vs. actual behavior. |
| Code: fix, feature, or plugin | Pull request to erxes/erxes | Finish Local Setup first, then Contribute to codebase for the workflow, Code Standards, and Testing. New plugins start with pnpm create-plugin; see Create a Plugin. |
| Documentation | erxes/erxes-global-profile, markdown/*.mdx | See How the public docs are maintained. |
| Translations | backend/gateway/src/locales/<lng>/<namespace>.json, or a plugin's own src/locales (for example frontline_api/src/locales) | The gateway serves these files at /locales/:lng/:file, falling back to files fetched from plugin services, and core-ui loads them with i18next-http-backend (config). Supported languages are en and mn. CONTRIBUTING.md points existing translation work to Transifex. |
| Questions | Discord or a GitHub issue | Ask before you introduce a new pattern. |
The repository has no issue or pull request templates: .github/ contains only workflows/. The conventions above come from CONTRIBUTING.md, not from a form. Issues labeled bug or sentry are forwarded to an internal listener by auto-issue-webhook.yml, so label bug reports accurately.
HACKTOBERFEST.md is a welcome note for Hacktoberfest 2025. It repeats the branch prefixes (fix/, docs/, feat/) and asks for quality over quantity; it adds no separate process.
Code of conduct
CODE_OF_CONDUCT.md is the Contributor Covenant 1.4. It applies in project spaces and wherever you represent the project. Report abusive behavior to [email protected]; maintainers may remove contributions or ban contributors who violate it.
Report a security vulnerability
Do not open a public issue for a vulnerability
Email [email protected] with a description, the steps you took, affected versions, and known mitigations. SECURITY.md states a 90-day disclosure timeline. The repository has no private advisory form beyond this email.
License implications for contributors
LICENSE.mdplaces everything under AGPLv3 except plugins whose name ends in-eeunder anee/directory (Enterprise Edition, governed byee/LICENSE; see https://erxes.io/pricing/enterprise-edition) and third-party components under their own licenses.LICENSE.mdalso states that erxes may not be hosted as a SaaS product that competes with erxes Inc.- The root
package.jsondeclares"license": "MIT". This contradictsLICENSE.mdand the AGPLv3 badge inREADME.md; treatLICENSE.mdas the governing text and ask maintainers if the distinction matters for your use. - There is no CLA or DCO file. Unless a maintainer states otherwise, your pull request is contributed under the repository license.
How the public docs are maintained
The pages on this site are MDX files in erxes/erxes-global-profile under markdown/, one file per slug. A page is published only when it is registered in constants/docs.ts and imported in markdown/registry.ts; adding a file alone does nothing. When you edit a page, check every path, command, and operation name against the code it links.