Skip to content

Commit 1fab072

Browse files
authored
Several "community health" requirements: (#105)
* Several "community health" requirements: - CODE_OF_CONDUCT.md - taken from https://www.contributor-covenant.org - CONTRIBUTING.md - .github/pull_request_template.md - boilerplate template Minor updates to README.md and SECURITY.md
1 parent 34526b1 commit 1fab072

File tree

5 files changed

+188
-2
lines changed

5 files changed

+188
-2
lines changed

.github/pull_request_template.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
Fixes # .
2+
3+
Changes proposed in this pull request:
4+
-
5+
-
6+
-
7+
8+
@deepfence/engineering

CODE_OF_CONDUCT.md

Lines changed: 134 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,134 @@
1+
2+
# Contributor Covenant Code of Conduct
3+
4+
## Our Pledge
5+
6+
We as members, contributors, and leaders pledge to make participation in our
7+
community a harassment-free experience for everyone, regardless of age, body
8+
size, visible or invisible disability, ethnicity, sex characteristics, gender
9+
identity and expression, level of experience, education, socio-economic status,
10+
nationality, personal appearance, race, caste, color, religion, or sexual
11+
identity and orientation.
12+
13+
We pledge to act and interact in ways that contribute to an open, welcoming,
14+
diverse, inclusive, and healthy community.
15+
16+
## Our Standards
17+
18+
Examples of behavior that contributes to a positive environment for our
19+
community include:
20+
21+
* Demonstrating empathy and kindness toward other people
22+
* Being respectful of differing opinions, viewpoints, and experiences
23+
* Giving and gracefully accepting constructive feedback
24+
* Accepting responsibility and apologizing to those affected by our mistakes,
25+
and learning from the experience
26+
* Focusing on what is best not just for us as individuals, but for the overall
27+
community
28+
29+
Examples of unacceptable behavior include:
30+
31+
* The use of sexualized language or imagery, and sexual attention or advances of
32+
any kind
33+
* Trolling, insulting or derogatory comments, and personal or political attacks
34+
* Public or private harassment
35+
* Publishing others' private information, such as a physical or email address,
36+
without their explicit permission
37+
* Other conduct which could reasonably be considered inappropriate in a
38+
professional setting
39+
40+
## Enforcement Responsibilities
41+
42+
Community leaders are responsible for clarifying and enforcing our standards of
43+
acceptable behavior and will take appropriate and fair corrective action in
44+
response to any behavior that they deem inappropriate, threatening, offensive,
45+
or harmful.
46+
47+
Community leaders have the right and responsibility to remove, edit, or reject
48+
comments, commits, code, wiki edits, issues, and other contributions that are
49+
not aligned to this Code of Conduct, and will communicate reasons for moderation
50+
decisions when appropriate.
51+
52+
## Scope
53+
54+
This Code of Conduct applies within all community spaces, and also applies when
55+
an individual is officially representing the community in public spaces.
56+
Examples of representing our community include using an official e-mail address,
57+
posting via an official social media account, or acting as an appointed
58+
representative at an online or offline event.
59+
60+
## Enforcement
61+
62+
Instances of abusive, harassing, or otherwise unacceptable behavior may be
63+
reported to the community leaders responsible for enforcement at
64+
**community *at* deepfence *dot* io**.
65+
All complaints will be reviewed and investigated promptly and fairly.
66+
67+
All community leaders are obligated to respect the privacy and security of the
68+
reporter of any incident.
69+
70+
## Enforcement Guidelines
71+
72+
Community leaders will follow these Community Impact Guidelines in determining
73+
the consequences for any action they deem in violation of this Code of Conduct:
74+
75+
### 1. Correction
76+
77+
**Community Impact**: Use of inappropriate language or other behavior deemed
78+
unprofessional or unwelcome in the community.
79+
80+
**Consequence**: A private, written warning from community leaders, providing
81+
clarity around the nature of the violation and an explanation of why the
82+
behavior was inappropriate. A public apology may be requested.
83+
84+
### 2. Warning
85+
86+
**Community Impact**: A violation through a single incident or series of
87+
actions.
88+
89+
**Consequence**: A warning with consequences for continued behavior. No
90+
interaction with the people involved, including unsolicited interaction with
91+
those enforcing the Code of Conduct, for a specified period of time. This
92+
includes avoiding interactions in community spaces as well as external channels
93+
like social media. Violating these terms may lead to a temporary or permanent
94+
ban.
95+
96+
### 3. Temporary Ban
97+
98+
**Community Impact**: A serious violation of community standards, including
99+
sustained inappropriate behavior.
100+
101+
**Consequence**: A temporary ban from any sort of interaction or public
102+
communication with the community for a specified period of time. No public or
103+
private interaction with the people involved, including unsolicited interaction
104+
with those enforcing the Code of Conduct, is allowed during this period.
105+
Violating these terms may lead to a permanent ban.
106+
107+
### 4. Permanent Ban
108+
109+
**Community Impact**: Demonstrating a pattern of violation of community
110+
standards, including sustained inappropriate behavior, harassment of an
111+
individual, or aggression toward or disparagement of classes of individuals.
112+
113+
**Consequence**: A permanent ban from any sort of public interaction within the
114+
community.
115+
116+
## Attribution
117+
118+
This Code of Conduct is adapted from the [Contributor Covenant][homepage],
119+
version 2.1, available at
120+
[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1].
121+
122+
Community Impact Guidelines were inspired by
123+
[Mozilla's code of conduct enforcement ladder][Mozilla CoC].
124+
125+
For answers to common questions about this code of conduct, see the FAQ at
126+
[https://www.contributor-covenant.org/faq][FAQ]. Translations are available at
127+
[https://www.contributor-covenant.org/translations][translations].
128+
129+
[homepage]: https://www.contributor-covenant.org
130+
[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html
131+
[Mozilla CoC]: https://github.com/mozilla/diversity
132+
[FAQ]: https://www.contributor-covenant.org/faq
133+
[translations]: https://www.contributor-covenant.org/translations
134+

CONTRIBUTING.md

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
# Contributing to ThreatMapper
2+
3+
First off, thank you for taking the time to contribute!
4+
5+
Here are some important resources:
6+
7+
* [Security Policy](SECURITY.md): If you need to share a security vulnerability, please refer to our Security Policy.
8+
* [Slack Discussions](https://join.slack.com/t/deepfence-community/shared_invite/zt-podmzle9-5X~qYx8wMaLt9bGWwkSdgQ): Any questions - join us on Slack
9+
* [Documentation](https://github.com/deepfence/ThreatMapper/wiki): Find and contribute to ThreatMapper documentation on the wiki.
10+
* [ThreatMapper License](LICENSE): ThreatMapper is 100% open source, using the Apache 2.0 license.
11+
* [Contributor License](https://docs.github.com/en/github/site-policy/github-terms-of-service#6-contributions-under-repository-license): The Apache 2.0 license applies to all contributions offered to the ThreatMapper project.
12+
* [Code of Conduct](CODE_OF_CONDUCT.md): The ThreatMapper community strives to be open and welcoming to all.
13+
14+
## How can I contribute?
15+
16+
### I'm having difficulty installing, operating or building ThreatMapper
17+
18+
Head over to our [Community Slack](https://join.slack.com/t/deepfence-community/shared_invite/zt-podmzle9-5X~qYx8wMaLt9bGWwkSdgQ) and share what's going on. It's generally useful to include details of your installation, as ThreatMapper is under constant development and we fix bugs fast. `docker images list` and `docker ps -a`, or the equivalent Kubernetes commands are a good start. Logs from any containers that may be misbehaving are also useful.
19+
20+
### I think I have found a bug in ThreatMapper
21+
22+
If you believe you've found a security vulnerability, please refer to our [Security Policy](SECURITY.md).
23+
24+
For all other bugs, please [first check if the issue has already been opened](https://github.com/deepfence/ThreatMapper/issues). If so, go ahead and add details to the existing issue.
25+
26+
If the bug appears to be new, please [open a new GitHub Bug report](https://github.com/deepfence/ThreatMapper/issues/new/choose). The template will prompt you for the information that will help us to understand and address the issue.
27+
28+
### I'd like to share a change to ThreatMapper
29+
30+
Thank you. Please send a [GitHub Pull Request to ThreatMapper](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/about-pull-requests) with a clear explanation of what you're seeking to achieve, and what you have done.
31+
32+
Code Style: we're flexible and accomodating. Copy the style of the code adjacent to your contributions, keep it clear and easy to understand for other developers and we're all good.
33+
34+
### I have an idea for an enhancement to ThreatMapper
35+
36+
If it's a well-formed enhancement, please [open a new GitHub Feature request](https://github.com/deepfence/ThreatMapper/issues/new/choose). Explain the enhancement and any supporting information - who it benefits, why it's important etc.
37+
38+
If you'd like to discuss the idea before proposing it on GitHub, share it on our [Community Slack](https://join.slack.com/t/deepfence-community/shared_invite/zt-podmzle9-5X~qYx8wMaLt9bGWwkSdgQ) and we will work through it together.
39+
40+
## I'd like to talk to someone directly
41+
42+
You can reach out to the ThreatMapper community leads at **community *at* deepfence *dot* io**.

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -230,7 +230,7 @@ Please share any feature requests or bug reports: https://github.com/deepfence/T
230230

231231
# Security and Support
232232

233-
For any security-related issues in the ThreatMapper project, contact productsecurity at deepfence dot io.
233+
For any security-related issues in the ThreatMapper project, contact **productsecurity *at* deepfence *dot* io**.
234234

235235
Please file Github issues as needed, and join the Deepfence Community [Slack channel](https://join.slack.com/t/deepfence-community/shared_invite/zt-podmzle9-5X~qYx8wMaLt9bGWwkSdgQ).
236236

SECURITY.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,3 @@
1-
Any vulnerabilities found in this source code may please be reported to productsecurity at deepfence dot io in complete confidence.
1+
Please report any potential security vulnerabilities to **productsecurity *at* deepfence *dot* io**.
2+
3+
Deepfence will endeavour to respond within 3 working days, and treats all security notifications in full confidence.

0 commit comments

Comments
 (0)