Prometheus
DE EN

Documentation · 09 / 09

Code of Conduct

Contributor Covenant v2.1, plus two project-specific tightenings that follow from Open Data.

Source CODE_OF_CONDUCT.mdReading time ~1 min

This project follows the Contributor Covenant v2.1.

The full text is binding; a German translation is recommended, but in case of conflict the English original governs:

Specifics for this project#

In addition to the Covenant, two tightenings apply that follow from the Open Data nature of the platform:

  1. No re-identification research against live data sets without prior disclosure. A researcher who develops a method by which an Open Data snapshot could be traced back to individuals despite k-anon reports it via SECURITY.md before demonstrating it publicly. We follow responsible disclosure — the usual window is 90 days.
  2. No spam against the federation. Submission spam, reach inflation against individual packages, botnet attempts against mirrors and the like are treated as a violation — even where no specific person is harassed. The anti-Sybil mechanics from concept/ADR-v2-0007 enforce this technically; this Code of Conduct enforces it socially.

Disclosure & escalation#

  • Violations in code, commits or PRs: an issue in the repository, or directly to conduct@<TODO-foundation-domain> (the address follows once the foundation is attached, see concept/06-offene-punkte.md P1-6).
  • Security-relevant findings: take the SECURITY.md path, not the public issue tracker.
  • Escalation for maintainer violations: the second maintainer track (see MAINTAINERS.md) is the fallback path.

The maintainers reserve the right to remove comments, commits, issues and PRs that do not comply with this Code of Conduct, and to exclude people temporarily or permanently.