Skip to content

Latest commit

 

History

History
242 lines (164 loc) · 8.66 KB

File metadata and controls

242 lines (164 loc) · 8.66 KB

Code of Conduct

🤝 Our Pledge

We as members, contributors, and maintainers pledge to make participation in our community a harassment-free experience for everyone, regardless of age, body size, visible or invisible disability, ethnicity, sex characteristics, gender identity and expression, level of experience, education, socio-economic status, nationality, personal appearance, race, caste, color, religion, or sexual identity and orientation.

We pledge to act and interact in ways that contribute to an open, welcoming, diverse, inclusive, and healthy community focused on email security for all.

🎯 Our Standards

Positive Behavior (Encouraged)

Be Respectful

  • Demonstrating empathy and kindness toward other people
  • Being respectful of differing opinions, viewpoints, and experiences
  • Giving and gracefully accepting constructive feedback

Be Inclusive

  • Using welcoming and inclusive language
  • Respecting people's pronouns and names
  • Acknowledging and learning from mistakes

Be Collaborative

  • Focusing on what is best for the community and users
  • Showing empathy towards other community members
  • Helping newcomers get started

Be Professional

  • Accepting responsibility and apologizing for mistakes
  • Focusing on technical merit over personal preferences
  • Being open to learning and growth

Be Transparent

  • Communicating clearly and honestly
  • Explaining decisions and technical choices
  • Documenting work for future contributors

Unacceptable Behavior (Prohibited)

Harassment

  • Trolling, insulting/derogatory comments, and personal or political attacks
  • Public or private harassment
  • Sexual attention or advances of any kind

Discrimination

  • Discriminatory jokes and language
  • Exclusionary behavior or gatekeeping
  • Assuming incompetence based on identity

Privacy Violations

  • Publishing others' private information without explicit permission
  • Doxxing or threatening to reveal private information

Dishonesty

  • Deliberately spreading misinformation
  • Plagiarism or claiming others' work as your own
  • Sockpuppeting or astroturfing

Professional Misconduct

  • Sustained disruption of discussions or development
  • Repeatedly ignoring community standards
  • Abusing maintainer privileges

🛡️ Security-Specific Standards

Given that DKIM Verifier is a security-critical project:

Required Practices

Responsible Disclosure

  • Never publicly disclose security vulnerabilities before patches
  • Follow SECURITY.md guidelines for reporting
  • Allow maintainers reasonable time to respond

Security-Conscious Development

  • Consider security implications of all code changes
  • Document potential security impacts in PRs
  • Err on side of caution for authentication/crypto code

Privacy Respect

  • Never request user emails or private data in issues
  • Redact sensitive information from bug reports
  • Respect user privacy in all interactions

Prohibited Practices

Security Violations

  • Weaponizing vulnerabilities before disclosure
  • Attempting to exploit users through malicious contributions
  • Social engineering or phishing community members

Bad Faith Security Reports

  • Filing frivolous "security" reports for attention
  • Demanding bounties when none are offered
  • Threatening public disclosure without reasonable timeline

🌡️ Emotional Safety

We follow principles from the Compassionate Code Contribution Protocol (CCCP):

Emotional Temperature

Contributors should feel psychologically safe to:

  • Ask "beginner" questions without shame
  • Admit mistakes and learn from them
  • Experiment without fear of harsh criticism
  • Disagree respectfully on technical matters

Reversibility

  • Code can be reverted; relationships cannot
  • Assume good intentions; clarify before criticizing
  • Focus feedback on code, not people
  • Celebrate learning over perfection

Anxiety Reduction

  • Clear, kind communication
  • Transparent decision-making
  • Predictable review processes
  • Acknowledging contributions promptly

👮 Enforcement Responsibilities

Maintainer Responsibilities

Community maintainers are responsible for clarifying and enforcing our standards of acceptable behavior and will take appropriate and fair corrective action in response to any behavior that they deem inappropriate, threatening, offensive, or harmful.

Maintainers have the right and responsibility to:

  • Remove, edit, or reject comments, commits, code, issues, and other contributions
  • Ban temporarily or permanently any contributor for behaviors deemed inappropriate

Scope

This Code of Conduct applies within all community spaces (GitHub, email, chat, in-person events) and when an individual is representing the project or community in public spaces.

📢 Reporting Violations

How to Report

  1. Email Maintainers: See MAINTAINERS.md for contact information
  2. Private Message: Contact any maintainer privately
  3. Anonymous Form: (To be implemented)

What to Include

  • Description of the incident
  • When and where it occurred
  • Who was involved
  • Any relevant screenshots or logs
  • Impact on you or others

Confidentiality

All reports will be handled with strictest confidence. We will not share:

  • Reporter's identity (unless they explicitly allow it)
  • Details beyond what's necessary for resolution
  • Information with anyone not involved in enforcement

⚖️ Enforcement Guidelines

Maintainers will follow these Community Impact Guidelines:

1. Correction (Minor Infraction)

Community Impact: Use of inappropriate language or other unprofessional behavior.

Consequence: Private, written warning from maintainers, with clarity around the nature of the violation and why it was inappropriate. A public apology may be requested.

2. Warning (Moderate Infraction)

Community Impact: A violation through a single incident or series of actions.

Consequence: Warning with consequences for continued behavior. No interaction with people involved (including community members) for a specified period. This includes avoiding interactions in community spaces and external channels. Violating these terms may lead to temporary or permanent ban.

3. Temporary Ban (Serious Infraction)

Community Impact: Serious violation, including sustained inappropriate behavior.

Consequence: Temporary ban from any interaction or public communication with the community for a specified period. No public or private interaction with people involved during this period. Violating these terms may lead to permanent ban.

4. Permanent Ban (Severe/Repeated Infractions)

Community Impact: Pattern of violation, harassment, or aggression toward others.

Consequence: Permanent ban from all community interaction.

🔄 Appeals Process

If you believe an enforcement decision was made in error:

  1. Email maintainers within 14 days of decision
  2. Explain why you believe the decision was incorrect
  3. Provide any additional context or evidence
  4. Maintainers will review and respond within 7 days

Appeals are handled by maintainers who were not involved in the original decision when possible.

🌟 Positive Reinforcement

We believe in recognizing positive contributions:

  • Helpful Community Members: Acknowledged in CHANGELOG
  • Quality Contributors: Advanced through TPCF perimeters
  • Exceptional Work: Featured in project updates
  • Long-term Contributors: Listed in MAINTAINERS.md

📚 Attribution

This Code of Conduct is adapted from:

🔗 Related Documents

  • CONTRIBUTING.md: Contribution guidelines and TPCF
  • SECURITY.md: Security vulnerability reporting
  • MAINTAINERS.md: Current maintainer contacts

📞 Contact

  • General Questions: GitHub Discussions
  • Code of Conduct Violations: See MAINTAINERS.md for private contact
  • Security Issues: See SECURITY.md

📝 Changes to This Document

This Code of Conduct may be revised from time to time. Major changes will be announced and subject to community feedback. Check the Git history for version tracking.

Version: 1.0 Last Updated: 2025-11-22 Effective Date: 2025-11-22


Remember: We're all here to make email safer. Let's do it together with kindness, professionalism, and respect. 🛡️💙