From 2b9392a60fc7d0914f5fb2576d6ecf6afcc736b9 Mon Sep 17 00:00:00 2001 From: Sharad Date: Sun, 13 Sep 2026 08:07:21 +0000 Subject: [PATCH 1/2] Add SECURITY.md, Contributor Covenant, and CODEOWNERS Adds private vulnerability reporting guidance, a standard code of conduct with maintainer enforcement contact, minimal CODEOWNERS for canonical paths, and routes security reports away from public issues in SUPPORT.md. Fixes conorbronsdon/avoid-ai-writing#255 Co-authored-by: Sharad. --- .github/CODEOWNERS | 7 +++ CODE_OF_CONDUCT.md | 135 +++++++++++++++++++++++++++++++++++++++++++++ SECURITY.md | 23 ++++++++ SUPPORT.md | 2 + 4 files changed, 167 insertions(+) create mode 100644 .github/CODEOWNERS create mode 100644 CODE_OF_CONDUCT.md create mode 100644 SECURITY.md diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 00000000..983649e6 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,7 @@ +# Default owner for review requests +* @conorbronsdon + +# Canonical skill and detector sources +/SKILL.md @conorbronsdon +/references/patterns.md @conorbronsdon +/detector/ @conorbronsdon diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 00000000..94fbef13 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,135 @@ +# Contributor Covenant Code of Conduct + +## Our Pledge + +We as members, contributors, and leaders pledge to make participation in our +community a harassment-free experience for everyone, regardless of age, body +size, visible or invisible disability, ethnicity, sex characteristics, gender +identity and expression, level of experience, education, socio-economic status, +nationality, personal appearance, race, caste, color, religion, or sexual +identity and orientation. + +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards + +Examples of behavior that contributes to a positive environment for our +community include: + +* Demonstrating empathy and kindness toward other people +* Being respectful of differing opinions, viewpoints, and experiences +* Giving and gracefully accepting constructive feedback +* Accepting responsibility and apologizing to those affected by our mistakes, + and learning from the experience +* Focusing on what is best not just for us as individuals, but for the overall + community + +Examples of unacceptable behavior include: + +* The use of sexualized language or imagery, and sexual attention or advances of + any kind +* Trolling, insulting or derogatory comments, and personal or political attacks +* Public or private harassment +* Publishing others' private information, such as a physical or email address, + without their explicit permission +* Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Enforcement Responsibilities + +Community leaders are responsible for clarifying and enforcing our standards of +acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, offensive, +or harmful. + +Community leaders have the right and responsibility to remove, edit, or reject +comments, commits, code, wiki edits, issues, and other contributions that are +not aligned to this Code of Conduct, and will communicate reasons for moderation +decisions when appropriate. + +## Scope + +This Code of Conduct applies within all community spaces, and also applies when +an individual is officially representing the community in public spaces. +Examples of representing our community include using an official email address, +posting via an official social media account, or acting as an appointed +representative at an online or offline event. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the community leaders responsible for enforcement at +[@conorbronsdon](https://github.com/conorbronsdon) on GitHub (for example via +a direct message when available, or by referencing this policy in a private +channel the maintainer provides). + +All complaints will be reviewed and investigated promptly and fairly. + +All community leaders are obligated to respect the privacy and security of the +reporter of any incident. + +## Enforcement Guidelines + +Community leaders will follow these Community Impact Guidelines in determining +the consequences for any action they deem in violation of this Code of Conduct: + +### 1. Correction + +**Community Impact**: Use of inappropriate language or other behavior deemed +unprofessional or unwelcome in the community. + +**Consequence**: A private, written warning from community leaders, providing +clarity around the nature of the violation and an explanation of why the +behavior was inappropriate. A public apology may be requested. + +### 2. Warning + +**Community Impact**: A violation through a single incident or series of +actions. + +**Consequence**: A warning with consequences for continued behavior. No +interaction with the people involved, including unsolicited interaction with +those enforcing the Code of Conduct, for a specified period of time. This +includes avoiding interactions in community spaces as well as external channels +like social media. Violating these terms may lead to a temporary or permanent +ban. + +### 3. Temporary Ban + +**Community Impact**: A serious violation of community standards, including +sustained inappropriate behavior. + +**Consequence**: A temporary ban from any sort of interaction or public +communication with the community for a specified period of time. No public or +private interaction with people involved, including unsolicited interaction +with those enforcing the Code of Conduct, is allowed during this period. +Violating these terms may lead to a permanent ban. + +### 4. Permanent Ban + +**Community Impact**: Demonstrating a pattern of violation of community +standards, including sustained inappropriate behavior, harassment of an +individual, or aggression toward or disparagement of classes of individuals. + +**Consequence**: A permanent ban from any sort of public interaction within the +community. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], +version 2.1, available at +[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1]. + +Community Impact Guidelines were inspired by +[Mozilla's code of conduct enforcement ladder][Mozilla CoC]. + +For answers to common questions about this code of conduct, see the FAQ at +[https://www.contributor-covenant.org/faq][FAQ]. Translations are available at +[https://www.contributor-covenant.org/translations][translations]. + +[homepage]: https://www.contributor-covenant.org +[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html +[Mozilla CoC]: https://github.com/mozilla/diversity +[FAQ]: https://www.contributor-covenant.org/faq +[translations]: https://www.contributor-covenant.org/translations diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..7fb84743 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,23 @@ +# Security Policy + +## Supported versions + +Security fixes target the current `main` branch and the latest [release tag](https://github.com/conorbronsdon/avoid-ai-writing/releases). Older tags are not routinely patched unless the same flaw affects a supported branch. + +## Reporting a vulnerability + +Do **not** file a public issue for an undisclosed security problem. This project runs in CI, pre-commit hooks, and local tooling on other people's machines; public reports can put users at risk before a fix ships. + +Report vulnerabilities through [GitHub private vulnerability reporting](https://github.com/conorbronsdon/avoid-ai-writing/security/advisories/new) for this repository. If that form is unavailable, contact [@conorbronsdon](https://github.com/conorbronsdon) through GitHub's private communication options instead of the public issue tracker. + +Include: + +- Affected components (for example `detector/`, `scripts/`, `bin/`, or packaged plugin paths) +- Version, tag, or commit SHA +- Steps to reproduce and realistic impact (code execution, path traversal, supply-chain via install scripts, etc.) + +## Response expectations + +- **Acknowledgment** within 7 business days for reports that appear actionable. +- **Status updates** at least every 14 days until the issue is fixed, declined with explanation, or closed as duplicate. +- **Disclosure** coordinated with the reporter after a fix is available; credit on request. diff --git a/SUPPORT.md b/SUPPORT.md index 38c4ace1..75b713e4 100644 --- a/SUPPORT.md +++ b/SUPPORT.md @@ -5,3 +5,5 @@ For bugs, routing problems, false positives, packaging issues, or ChatGPT and Co https://github.com/conorbronsdon/avoid-ai-writing/issues Include the plugin version, the host surface you used, the expected behavior, and a minimal reproduction. Do not post confidential drafts or personal information in a public issue. + +For **security vulnerabilities**, do not use the public issue tracker. Follow [SECURITY.md](SECURITY.md) and report through GitHub private vulnerability reporting or the maintainer contact listed there. From cfd32868d4ff1e05696aa7a0d980681ce9aba441 Mon Sep 17 00:00:00 2001 From: Conor Bronsdon <120674402+conorbronsdon@users.noreply.github.com> Date: Mon, 14 Sep 2026 00:34:55 -0700 Subject: [PATCH 2/2] docs: scope proposed conduct commitments to maintainer reports --- CODE_OF_CONDUCT.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md index 84ebf101..dfdaef22 100644 --- a/CODE_OF_CONDUCT.md +++ b/CODE_OF_CONDUCT.md @@ -70,10 +70,11 @@ For abuse on GitHub, use GitHub's existing Reports sent to GitHub Support are handled by GitHub; they do not establish a private reporting route to this project's maintainers. -All complaints will be reviewed and investigated promptly and fairly. +If adopted, project maintainers would review complaints received through the +designated project contact promptly and fairly. -All community leaders are obligated to respect the privacy and security of the -reporter of any incident. +Under this proposed policy, all community leaders would be obligated to respect +the privacy and security of the reporter of any incident. ## Enforcement Guidelines