Ansible-Roles/roles/openssh/docs/CODE_OF_CONDUCT.md
Alexander Kazantsev 7ab93a673b deploy openssh
2026-05-12 18:38:21 +03:00

10 KiB

Code of Conduct

Our Pledge

We as contributors, maintainers, and participants pledge to make participation in the ansible-role-openssh_server project a welcoming, safe, and equitable experience for everyone.

We are committed to fostering an inclusive community where all people can contribute, regardless of age, body size, disability (visible or invisible), ethnicity, gender identity and expression, level of experience, education, socioeconomic status, nationality, personal appearance, race, religion, sexual identity and orientation, or any other characteristic.

We pledge to act and interact in ways that contribute to an open, welcoming, diverse, and healthy community focused on improving SSH security for everyone.

Our Standards

Encouraged Behaviors

We encourage community members to:

  • Respect the community's purpose: Keep discussions and contributions focused on SSH security, OpenSSH hardening, compliance frameworks, and related topics
  • Engage with kindness and empathy: Treat all participants with respect and professionalism
  • Accept different viewpoints: Understand that security professionals come from diverse backgrounds and may have different approaches
  • Take responsibility: Acknowledge mistakes, apologize to those affected, and learn from the experience
  • Give constructive feedback: Provide helpful, actionable suggestions backed by authoritative sources
  • Repair harm when possible: Make amends when you've made a mistake
  • Promote community well-being: Act in ways that benefit the broader security community

Unacceptable Behaviors

The following behaviors are not acceptable in our community:

  • Harassment: Offensive comments, personal attacks, unwelcome sexual attention, or any form of harassment
  • Character attacks: Trolling, insulting or derogatory comments, and personal or political attacks
  • Stereotyping: Making assumptions about people based on their identity or characteristics
  • Inappropriate content: Sexualized language, imagery, or unwelcome advances
  • Privacy violations: Publishing others' private information (doxxing) without explicit permission
  • Endangerment: Threats of violence or inciting violence against any individual
  • Dishonesty: False security claims, unverified CVE status, or intentionally misleading information
  • Malicious contributions: Submitting intentionally vulnerable configurations or malicious code
  • Disruptive behavior: Sustained disruption of discussions or deliberately off-topic conversations

Scope

This Code of Conduct applies in all project spaces, including but not limited to:

  • GitHub repository (issues, pull requests, discussions)
  • Project documentation and wikis
  • Email communications
  • Chat platforms (if established)
  • In-person or virtual events representing the project
  • Social media when representing the project

This code also applies when representing the project in public spaces.

Enforcement

Reporting Issues

If you experience or witness unacceptable behavior, please report it promptly to the project maintainers:

Reporting Methods:

  • GitHub: Use the "Report abuse" feature on GitHub
  • Email: Contact the maintainer directly (see repository for contact information)
  • Private report: For sensitive situations, request a private discussion

What to include in your report:

  • Your contact information
  • Description of the incident (what happened, when, where)
  • Any supporting evidence (links, screenshots with sensitive data removed)
  • Whether you'd like to remain anonymous
  • Any other relevant context

Investigation Process

All complaints will be:

  1. Reviewed as time permits: This is a volunteer-run hobby project, so please be patient
  2. Investigated thoroughly: We will gather information from all involved parties
  3. Kept confidential: Reporter privacy will be respected
  4. Handled impartially: All parties will be treated fairly
  5. Resolved appropriately: Based on the severity and context of the violation

Note: As this is a hobby project maintained by volunteers in their spare time, response times may vary. We appreciate your patience and understanding.

Enforcement Guidelines

We follow a graduated enforcement approach based on the severity and frequency of violations:

1. Warning (First Offense - Minor)

Appropriate for: Unintentional violations, tone issues, minor disruptions

Response:

  • Private written warning from maintainers
  • Explanation of the violation and why it was inappropriate
  • Request for apology (if applicable)
  • Guidance on expected future behavior

Impact: No immediate restrictions, but incident is documented

2. Temporarily Limited Activities (Second Offense or Moderate)

Appropriate for: Repeated minor violations, moderate harassment, false security claims

Response:

  • Temporary restriction from interaction (7-30 days)
  • May include:
    • Temporary ban from commenting on issues/PRs
    • Requirement for all contributions to be reviewed by maintainers
    • Prohibition from contacting specific community members

Impact: Limited participation for a defined period

3. Temporary Suspension (Serious Offense)

Appropriate for: Serious harassment, malicious contributions, pattern of violations

Response:

  • Temporary ban from all project participation (30-90 days)
  • Public statement about the suspension (without identifying details if reporter requests anonymity)
  • No interaction with project or community during suspension
  • Conditions for reinstatement clearly defined

Impact: Complete removal from community for a defined period

4. Permanent Ban (Severe or Repeated Violations)

Appropriate for: Severe harassment, threats of violence, intentional security sabotage, repeated violations after warnings

Response:

  • Permanent ban from all project participation
  • Public statement about the ban
  • Removal of previous contributions may be considered (in extreme cases)
  • Notification to relevant platforms (GitHub, etc.)

Impact: Permanent removal from community

Appeals Process

Anyone subject to enforcement may appeal by:

  1. Contacting the maintainers with additional context or information
  2. Requesting reconsideration of the decision

Appeals will be reviewed as time permits by uninvolved maintainers (if available) or community advisors.

Note: As a hobby project, appeals will be addressed when maintainers have capacity. We appreciate your patience.

Special Considerations for Security Projects

Because this project focuses on security, we have additional expectations:

Accuracy and Integrity

  • Verify security claims: All security-related statements must be backed by authoritative sources
  • Cite sources: When discussing CVEs, compliance requirements, or cryptographic standards, provide links
  • Admit uncertainty: If you're not sure about something, say so—guessing about security is dangerous
  • Correct errors promptly: If you make a mistake about security, acknowledge and correct it immediately

Responsible Disclosure

  • Report vulnerabilities privately: Never disclose security vulnerabilities publicly without coordinated disclosure
  • Respect embargo periods: Honor coordinated disclosure timelines
  • Credit researchers: Acknowledge those who responsibly report security issues

Professional Disagreement

Security professionals may have strong opinions about:

  • Cryptographic algorithms
  • Compliance framework interpretations
  • Risk assessment approaches
  • Configuration trade-offs

We expect:

  • Disagreement backed by research and sources
  • Respectful debate focused on technical merits
  • Willingness to agree to disagree
  • Recognition that perfect security doesn't exist—only risk management

Maintainer Responsibilities

Project maintainers are responsible for:

  • Clarifying and enforcing standards of acceptable behavior
  • Taking appropriate and fair corrective action in response to violations
  • Removing, editing, or rejecting contributions that violate this Code of Conduct
  • Communicating reasons for moderation decisions when appropriate
  • Leading by example in all community interactions

Maintainers who do not follow or enforce the Code of Conduct may face temporary or permanent consequences.

Positive Community Building

We encourage behaviors that build a healthy, productive community:

Knowledge Sharing

  • Share research and findings generously
  • Help newcomers learn about SSH security
  • Document your discoveries for others
  • Contribute to improving documentation

Constructive Feedback

  • Focus on the contribution, not the person
  • Provide specific, actionable suggestions
  • Acknowledge good work when you see it
  • Thank contributors for their efforts

Inclusive Language

  • Use inclusive pronouns and language
  • Avoid assumptions about technical background
  • Welcome questions from all skill levels
  • Explain jargon and acronyms

Recognition

  • Credit others' work and ideas
  • Acknowledge contributors in pull requests
  • Thank people who help you
  • Celebrate community achievements

Attribution

This Code of Conduct is adapted from:

It is tailored specifically for a security-focused open source project with additional considerations for accuracy, responsible disclosure, and professional technical disagreement.

Questions or Concerns

If you have questions about this Code of Conduct or need clarification:

  • Open a discussion on GitHub
  • Contact the maintainers privately
  • Suggest improvements via pull request

License

This Code of Conduct is licensed under Creative Commons Attribution-ShareAlike 4.0 International License.


Remember: This project exists to help administrators secure SSH servers and protect critical infrastructure. Our community interactions should reflect the same care and professionalism we expect in security work.

Thank you for helping make this a welcoming, productive, and secure community!


Last updated: 2025-10-05 Code of Conduct Version: 1.0