This project follows the Contributor Covenant v2.1.
The full text is binding; a German translation is recommended, but in case of conflict the English original governs:
- Full text (English, canonical): https://www.contributor-covenant.org/version/2/1/code_of_conduct/
- German translation: https://www.contributor-covenant.org/de/version/2/1/code_of_conduct/
Specifics for this project#
In addition to the Covenant, two tightenings apply that follow from the Open Data nature of the platform:
- No re-identification research against live data sets without prior disclosure. A researcher who develops a method by which an Open Data snapshot could be traced back to individuals despite k-anon reports it via
SECURITY.mdbefore demonstrating it publicly. We follow responsible disclosure — the usual window is 90 days. - No spam against the federation. Submission spam, reach inflation against individual packages, botnet attempts against mirrors and the like are treated as a violation — even where no specific person is harassed. The anti-Sybil mechanics from
concept/ADR-v2-0007enforce this technically; this Code of Conduct enforces it socially.
Disclosure & escalation#
- Violations in code, commits or PRs: an issue in the repository, or directly to
conduct@<TODO-foundation-domain>(the address follows once the foundation is attached, seeconcept/06-offene-punkte.mdP1-6). - Security-relevant findings: take the
SECURITY.mdpath, not the public issue tracker. - Escalation for maintainer violations: the second maintainer track (see
MAINTAINERS.md) is the fallback path.
The maintainers reserve the right to remove comments, commits, issues and PRs that do not comply with this Code of Conduct, and to exclude people temporarily or permanently.