Skip to content

Commit 608a970

Browse files
committed
Extended repository documentation for contributors
1 parent 2e7ecd7 commit 608a970

5 files changed

Lines changed: 529 additions & 0 deletions

File tree

‎CODE_OF_CONDUCT.md‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# Code of Conduct
2+
3+
We are committed to providing a welcoming and respectful environment for everyone participating in the development
4+
and maintenance of this project.
5+
6+
This project has adopted the Contributor Covenant Code of Conduct. Please read the full Code of Conduct at:
7+
8+
https://www.contributor-covenant.org/version/3/0/code_of_conduct/
9+
10+
## Reporting code of conduct issues
11+
12+
If you experience or witness unacceptable behaviour, please report it privately to the project maintainers by sending
13+
an email at [DIGIT-ITB@ec.europa.eu](mailto:DIGIT-ITB@ec.europa.eu).
14+
15+
Reports will be handled as confidentially as reasonably possible.

‎CONTRIBUTING.md‎

Lines changed: 196 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,196 @@
1+
# Contributing
2+
3+
These are the guidelines for contributors to the **Interoperability Test Bed's CSV validator**, subsequently referred to
4+
as the **Solution**. In the scope of this document the terms **You**, **Your**, and **Yourself** refer to yourself
5+
acting in the role of a prospective contributor.
6+
7+
## Introduction
8+
9+
Thank You for Your interest in contributing to this Solution.
10+
11+
The Solution is developed and maintained primarily by the European Commission. Contributions from external developers
12+
are welcome, although the project is not currently operated as a community-driven project.
13+
14+
The primary type of contribution that we encourage is feedback raised as issues in the current repository.
15+
The reason for this is to ensure the Solution always remains reusable for the widest set of users and use cases, while
16+
remaining true to its design principles. Nonetheless, we do also accept limited community contributions in the form of
17+
code, configuration and documentation, to be merged following an appropriate review and approval process by the
18+
Solution maintainers.
19+
20+
## Types of contribution
21+
22+
We distinguish the following types of contribution to the project:
23+
24+
1. **Contribution of feedback**
25+
26+
Providing feedback is the primary means of contribution that we encourage. Such feedback relates to feature requests,
27+
suggested improvements, and bug reports. Any user, including Yourself, is free to [raise a ticket](#issues) to provide
28+
such feedback.
29+
30+
2. **Minor code and configuration contributions**
31+
32+
We consider as minor contributions those that apply targeted corrections or improvements, affecting a limited set
33+
of resources. In these cases we prefer that You create a relevant [issue](#issues) first, and then link it
34+
to a [pull request](#pull-requests), to facilitate exchanges, traceability, and discoverability by other users.
35+
You are not required to sign a particular document, however You are encouraged to sign off commits with
36+
a GPG key. Please refer also to the section on [Minor Contributions](#minor-contributions) for additional information.
37+
38+
3. **Documentation contributions**
39+
40+
Contributions to documentation do not require You to raise a relevant [issue](#issues) first, only create a
41+
[pull request](#pull-requests) with the proposed changes. You are not required to sign a particular document, however
42+
You are encouraged to sign off commits with a GPG key.
43+
44+
4. **All other code and configuration contributions**
45+
46+
Code and configuration contributions that affect significant changes are typically not preferred. In all such cases
47+
You should raise an [issue](#issues) in advance to discuss with the Solution's maintainers. In case it is
48+
agreed to proceed with the contribution, please refer to the section on [Substantial Contributions](#substantial-contributions)
49+
for additional steps. In the end Your resulting contribution should be submitted as a [pull request](#pull-requests)
50+
for review by the Solution maintainers.
51+
52+
## Issues
53+
54+
You should use GitHub Issues for:
55+
56+
- Bug reports
57+
- Feature requests
58+
- Documentation issues
59+
- Raising questions
60+
- Other actionable project issues
61+
62+
In particular when creating a bug report, please provide extra information on the Solution's version that was used, the
63+
expected behaviour, test data to replicate, log extracts, screenshots, and any other pertinent information. Ensure You
64+
also check the history of issues to ensure that this has not already been raised and potentially addressed in a
65+
subsequent release or development build.
66+
67+
For security vulnerabilities, please follow the process described in [SECURITY.md](SECURITY.md) instead of opening a
68+
public issue.
69+
70+
## Development
71+
72+
See the project [README.md](README.md) for instructions on setting up the development environment, building the project,
73+
and testing Your changes. In doing so please:
74+
75+
- Follow the existing coding conventions.
76+
- Keep changes focused and avoid unrelated modifications.
77+
- Add or update tests where appropriate.
78+
- Update documentation when necessary.
79+
- Make sure the project builds and the relevant tests pass before submitting a pull request.
80+
81+
## Pull Requests
82+
83+
In the contribution scenarios where You expect to share code, configuration or documentation updates, please do so
84+
using a pull request. Pull requests should:
85+
86+
- Clearly describe what has been changed and why.
87+
- Include tests where appropriate.
88+
- Reference an existing issue when applicable.
89+
- Explain any relevant compatibility or behavioural changes.
90+
91+
All pull requests are subject to review and approval by the Solution maintainers. Submitting a pull request does not
92+
imply that the proposed change will be accepted.
93+
94+
Maintainers may request changes, propose an alternative implementation, or decline a contribution if it does not fit
95+
the Solution's scope, architecture, roadmap, or maintenance requirements.
96+
97+
## Code of Conduct
98+
99+
Please read and follow [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md) when participating in the project.
100+
101+
## Minor Contributions
102+
103+
Minor contributions to code and configuration resources may involve resources that are subject to intellectual property
104+
rights and copyright. In the case of such contributions, You agree that by submitting Your contributions You waive any
105+
intellectual property rights and copyright claims to Your contribution.
106+
107+
Contributions that involve third-party software libraries that are not already included in the Solution are never
108+
considered minor. The same applies for existing third-party software libraries for which the contribution changes the
109+
Solution's included version numbers. In such cases You are invited to raise a relevant [issue](#issues).
110+
111+
## Substantial Contributions
112+
113+
When making a substantial code contribution, additional steps are needed from You. Please identify Yourself in one
114+
of the following sections and follow the procedure described there.
115+
116+
1. **EU Officials (from the European Commission, European Parliament, European Council, the Council of the European,
117+
Court of Justice of the European Union, European Court of Auditors, European Economic and Social Committee,
118+
Committee of the Regions)**
119+
120+
The rights in Your contribution are the property of the European Union. When sending a contribution You need to
121+
sign off the commits You make with a GPG key. By signing off Your commits, You indicate that You have read
122+
[these terms](etc/contributions/DCO.md) and that You agree with these.
123+
124+
2. **MS Administrations, other EU Institutions and Bodies with separate
125+
legal personality (e.g. Executive, Decentralized Agencies, European
126+
Central Bank), universities, legal entities (NGOs, private
127+
companies)**
128+
129+
If the contribution comes from an administration of a Member State in the EU or other public administrations outside
130+
the EU, from an EU institution or body with legal personality, from a university or in general from a legal entity
131+
(NGO, private company etc.), the copyright belongs to the respective entity and hence we need to receive from You
132+
the right to use the contribution. For this to happen, please have Your legal representative sign the
133+
[Contributor Licence Agreement](etc/contributions/CLA.md) and send it to us by email at
134+
[DIGIT-ITB@ec.europa.eu](mailto:DIGIT-ITB@ec.europa.eu).
135+
136+
Any employee submitting a contribution on Your behalf needs to sign off the commits with a GPG key. By signing off
137+
the commit, the employee (individual) who submits a contribution indicates that he/she has read the terms of the
138+
[Contributor Licence Agreement](etc/contributions/CLA.md) and agrees with these.
139+
140+
3. **Individuals acting outside the performance of their duties or self-employed**
141+
142+
If You are an individual (natural person), either self-employed or working outside the performance of Your duties
143+
with Your employer, You own the rights in Your contribution and we need to receive from You the right to use such
144+
contribution. For this to happen, please sign the [Contributor Licence Agreement](etc/contributions/CLA.md) and send
145+
it to us by email at [DIGIT-ITB@ec.europa.eu](mailto:DIGIT-ITB@ec.europa.eu).
146+
147+
Additionally, please sign off on the commits You make with a GPG key.
148+
149+
4. **Individuals acting in connection with the performance of their duties**
150+
151+
If You are an employed individual (natural person) and the contribution can be considered as within Your authorised
152+
scope of work or line of duty, it is Your employer who holds the copyright in the contribution and hence You are in
153+
a position to give us a right to use it. For this reason, we kindly ask You to address Your employer and follow
154+
section 2 above.
155+
156+
To this end we need to receive from Your employer the signed [Contributor Licence Agreement](etc/contributions/CLA.md).
157+
158+
Additionally, please sign off on the commits You make with a GPG key.
159+
160+
### How to handle Your contribution
161+
162+
**Legal compliance:** Please ensure that, if Your contribution is based upon previous third-party work, such work that
163+
is covered under an appropriate (open source) licence that would not prevent it from being used in the project, under
164+
its established outbound licence. To this end, You need to ensure that there is no incompatibility between (i) any
165+
of the licences which cover the third-party work that You use or (ii) the licence of the project and the licences of
166+
any third-party work You may use within Your contribution (such incompatibilities would arise if You use GPL code in
167+
Your contribution for a project which is distributed under EUPL or MIT or if Your contribution is based both on Apache
168+
and GPL 2.0 only code). Please ensure that You are not violating the terms of any licence by using it within Your
169+
contribution. You are guaranteeing compliance with applicable (open source) licences under article 3 in the CLA. If You
170+
have doubts on the correct use of third-party software, You may address the Solution maintainers before committing code.
171+
172+
For any third-party work that You use within the contribution You submit us, You must retain all copyright and licence
173+
information (as available for instance in a specific 'Licence' file, 'Notice' file, in the headers of the sources of
174+
the used third-party work etc.).
175+
176+
We additionally have to request You to provide us with a list of third-party software (dependencies) You are using
177+
within Your contribution (i.e. a software bill of materials as required under good development practices for open
178+
source projects). Please provide it together with Your commit, in any format convenient for You. The software bill of
179+
materials can be generated using a code scanning tool or a package manager; however You must double-check the generated
180+
information and complement it if there is a need to do so.
181+
182+
Please make sure You read closely article 3 in the [Contributor Licence Agreement](etc/contributions/CLA.md) which
183+
specifically refers to these obligations.
184+
185+
We reserve the right to refuse Your contribution for non-compliance reasons or for not providing us with the required
186+
list of dependencies.
187+
188+
**Signing of the CLA:** Please note that the CLA You sign for this project does not apply to other projects of the EC.
189+
If You are contributing to several projects, You need to send a signed CLA for each of these.
190+
191+
We accept the following types of signatures for the CLA You return:
192+
193+
- electronic signatures using trusted service providers from the list available
194+
here: https://eidas.ec.europa.eu/efda/tl-browser/#/screen/home
195+
- wet signatures (handed signed) or
196+
- other digital solutions so long they are eIDAS compliant (e.g. open-pdf-sign)

‎SECURITY.md‎

Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
# Security Policy
2+
3+
This is the security policy related to the **Interoperability Test Bed's CSV validator**, subsequently referred to as
4+
the **Solution**.
5+
6+
## Introduction
7+
8+
This Solution is developed and maintained primarily by the European Commission. It is used by European Commission
9+
services, as well as by various other parties. The security of the Solution regardless of the use case for which it
10+
is being used, is of utmost importance to us.
11+
12+
## Reporting a Vulnerability
13+
14+
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions. If you
15+
believe you have found a security vulnerability in the Solution, please report it privately by sending an
16+
email to:
17+
18+
- [EC-DIGIT-SECURITY-ASSURANCE@ec.europa.eu](mailto:EC-DIGIT-SECURITY-ASSURANCE@ec.europa.eu): DIGIT's security assurance team.
19+
- [DIGIT-ITB@ec.europa.eu](mailto:DIGIT-ITB@ec.europa.eu): DIGIT's ITB support team.
20+
21+
Please include as much information as possible, including:
22+
23+
- A description of the vulnerability.
24+
- The affected version(s).
25+
- Steps to reproduce the issue.
26+
- A proof of concept or minimal reproduction, where available.
27+
- The potential impact.
28+
- Any relevant logs or error messages.
29+
- A suggested mitigation or fix, if available.
30+
31+
Please do not publicly disclose the vulnerability until the maintainers have had an opportunity to investigate it.
32+
33+
## Vulnerabilities in European Commission Services
34+
35+
This repository contains the Solution's software itself.
36+
37+
If you have identified a vulnerability in an internet-facing service operated by the European Commission, rather than
38+
in the software contained in this repository, please follow the European Commission's Vulnerability Disclosure Policy:
39+
40+
https://commission.europa.eu/legal-notice/vulnerability-disclosure-policy_en
41+
42+
## Security Updates
43+
44+
Security fixes will be released as appropriate to the affected versions. When reported vulnerabilities are found to
45+
be exploitable a patch fix shall be released as soon as possible.
46+
47+
Users are encouraged to keep their copy of the Solution software up to date and to monitor the repository's releases and
48+
security advisories.
49+
50+
## Third-Party Dependencies
51+
52+
Security vulnerabilities in third-party dependencies should normally be reported to the maintainers of the affected
53+
dependency.
54+
55+
The Test Bed team continuously monitors the security health of the Solution's third-party dependencies and proactively
56+
issues patch updates for the Solution where vulnerable dependencies are found to be exploitable. The Test Bed team
57+
may also choose to release patch updates addressing high-severity vulnerabilities in third-party libraries that are
58+
not exploitable, to facilitate automated security monitoring processes of downstream users.
59+
60+
If you find that a vulnerability in a third-party dependency is not sufficiently addressed, or leads to unexpected
61+
implications, please report it as described above.
62+
63+
## Responsible Disclosure
64+
65+
We ask security researchers and users to give the maintainers a reasonable opportunity to investigate and address
66+
security issues before publicly disclosing them.
67+
68+
We appreciate responsible security research and reports that help improve the security of the Solution.

0 commit comments

Comments
 (0)