-
Notifications
You must be signed in to change notification settings - Fork 78
docs: add code of conduct, contributing guide, issue and PR templates #8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
2 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,20 @@ | ||
| --- | ||
| name: Bug Report | ||
| about: Something isn't working | ||
| title: "" | ||
| labels: bug | ||
| assignees: '' | ||
| --- | ||
|
|
||
| **What happened?** | ||
|
|
||
| **What did you expect?** | ||
|
|
||
| **Steps to reproduce** | ||
| 1. | ||
| 2. | ||
|
|
||
| **Logs or errors** (if any) | ||
|
|
||
| ``` | ||
| ``` |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,20 @@ | ||
| --- | ||
| name: Feature Request | ||
| about: Suggest an idea | ||
| title: "" | ||
| labels: enhancement | ||
| assignees: '' | ||
| --- | ||
|
|
||
| ## Summary | ||
|
|
||
| A brief, one-line summary of the feature. | ||
|
|
||
| ## Motivation | ||
|
|
||
| Why is this feature needed? What problem does it solve or what workflow does it | ||
| improve? Link any related issues if applicable. | ||
|
|
||
| ## Proposed Solution | ||
|
|
||
| Describe how you envision this working. Be as specific as possible. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,14 @@ | ||
| **What does this PR do?** | ||
|
|
||
|
|
||
| **Related issues** | ||
|
|
||
|
|
||
| **How to test** | ||
|
|
||
|
|
||
| **Checklist** | ||
| - [ ] `ruff check .` and `ruff format --check .` pass | ||
| - [ ] `bandit -ll -ii -c pyproject.toml -r .` passes | ||
| - [ ] `pytest` passes | ||
| - [ ] Tests added/updated if needed |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,104 @@ | ||
| # Contributor Covenant Code of Conduct | ||
|
|
||
| ## Our Pledge | ||
|
|
||
| We as members, contributors, and leaders pledge to make participation in the | ||
| DeepZero community a harassment-free experience for everyone, regardless of age, | ||
| body size, visible or invisible disability, ethnicity, sex characteristics, | ||
| gender identity and expression, level of experience, education, socio-economic | ||
| status, nationality, personal appearance, race, caste, color, religion, or | ||
| sexual identity and orientation. | ||
|
|
||
| We pledge to act and interact in ways that contribute to an open, welcoming, | ||
| diverse, inclusive, and healthy community. | ||
|
|
||
| ## Our Standards | ||
|
|
||
| Examples of behavior that contributes to a positive environment: | ||
|
|
||
| - Using welcoming and inclusive language | ||
| - Being respectful of differing viewpoints and experiences | ||
| - Giving and gracefully accepting constructive feedback | ||
| - Accepting responsibility and apologizing to those affected by our mistakes, | ||
| and learning from the experience | ||
| - Focusing on what is best not just for us as individuals, but for the overall | ||
| community | ||
|
|
||
| Examples of unacceptable behavior: | ||
|
|
||
| - The use of sexualized language or imagery, and sexual attention or advances of | ||
| any kind | ||
| - Trolling, insulting or derogatory comments, and personal or political attacks | ||
| - Public or private harassment | ||
| - Publishing others' private information, such as a physical or email address, | ||
| without their explicit permission | ||
| - Other conduct which could reasonably be considered inappropriate in a | ||
| professional setting | ||
|
|
||
| ## Responsible Security Research | ||
|
|
||
| DeepZero is a vulnerability research pipeline engine. As a community built | ||
| around security tooling, we hold ourselves to an additional standard: | ||
|
|
||
| - **Use DeepZero for defensive research only.** Contributions and discussions | ||
| must focus on improving security posture, not enabling attacks. | ||
| - **Follow coordinated disclosure.** If your work with DeepZero uncovers a | ||
| real-world vulnerability, report it to the affected vendor before any public | ||
| disclosure. See our [Security Policy](SECURITY.md) for guidance. | ||
| - **Never share live exploits** or weaponized payloads in issues, discussions, | ||
| or pull requests. | ||
| - **Respect data boundaries.** Do not include proprietary binaries, copyrighted | ||
| corpora, or sensitive data in contributions. | ||
|
|
||
| ## Enforcement Responsibilities | ||
|
|
||
| Project maintainers are responsible for clarifying and enforcing our standards | ||
| of acceptable behavior and will take appropriate and fair corrective action in | ||
| response to any behavior that they deem inappropriate, threatening, offensive, | ||
| or harmful. | ||
|
|
||
| Project maintainers have the right and responsibility to remove, edit, or reject | ||
| comments, commits, code, wiki edits, issues, and other contributions that are | ||
| not aligned with this Code of Conduct, and will communicate reasons for | ||
| moderation decisions when appropriate. | ||
|
|
||
| ## Scope | ||
|
|
||
| This Code of Conduct applies within all community spaces, including the GitHub | ||
| repository, issue tracker, pull requests, discussions, and any other channels | ||
| associated with DeepZero. It also applies when an individual is officially | ||
| representing the community in public spaces. | ||
|
|
||
| ## Enforcement | ||
|
|
||
| Instances of abusive, harassing, or otherwise unacceptable behavior may be | ||
| reported to the project maintainers via: | ||
|
|
||
| - **GitHub**: Open a private report through the repository's security advisories | ||
| - **Email**: Contact a maintainer directly through the email listed on their | ||
| GitHub profile | ||
|
|
||
| All complaints will be reviewed and investigated promptly and fairly. All | ||
| maintainers are obligated to respect the privacy and security of the reporter. | ||
|
|
||
| ## Enforcement Guidelines | ||
|
|
||
| ### 1. Warning | ||
|
|
||
| For first-time or minor violations, maintainers will reach out privately to | ||
| explain what was inappropriate and why. The expectation is that the behavior | ||
| stops. | ||
|
|
||
| ### 2. Block | ||
|
|
||
| For repeated or severe violations, the individual will be blocked from the | ||
| repository, preventing further issues, comments, and pull requests. | ||
|
|
||
| ## Attribution | ||
|
|
||
| This Code of Conduct is adapted from the [Contributor Covenant][homepage], | ||
| version 2.1, available at | ||
| [https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1]. | ||
|
|
||
| [homepage]: https://www.contributor-covenant.org | ||
| [v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html | ||
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The Code of Conduct report instructions currently direct people to open a private report via the repository’s Security Advisories, which is intended for security vulnerabilities and can misroute conduct incidents. Consider pointing to a dedicated maintainer contact method for CoC reports (e.g., an email alias) and/or GitHub’s built-in reporting guidance, and keep Security Advisories reserved for SECURITY.md.