├── CODEOWNERS ├── README.md ├── CONTRIBUTING.md ├── catalog-info.yaml ├── CODE_OF_CONDUCT.md └── SECURITY.md /CODEOWNERS: -------------------------------------------------------------------------------- 1 | * @contentful/team-security 2 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # .github 2 | Repo for storing community health files. This includes CONTRIBUTING and CODE_OF_CONDUCT files. 3 | 4 | See https://help.github.com/en/articles/creating-a-default-community-health-file-for-your-organization 5 | -------------------------------------------------------------------------------- /CONTRIBUTING.md: -------------------------------------------------------------------------------- 1 | #Introduction 2 | 3 | We appreciate any community contributions to this project, whether in the form of issues or Pull Requests. 4 | 5 | If you have any questions or concerns please reach out to us either by filing an issue in the relevant repository or posting in the [Contentful Community Slack](https://www.contentful.com/slack/). 6 | -------------------------------------------------------------------------------- /catalog-info.yaml: -------------------------------------------------------------------------------- 1 | # Backstage documentation 2 | # https://backstage.io/docs/features/software-catalog/descriptor-format/ 3 | 4 | apiVersion: backstage.io/v1alpha1 5 | kind: Component 6 | metadata: 7 | name: .github 8 | description: Repo for storing community health files 9 | annotations: 10 | github.com/project-slug: contentful/.github 11 | contentful.com/service-tier: "4" 12 | 13 | tags: 14 | - tier-4 15 | spec: 16 | type: documentation 17 | lifecycle: production 18 | owner: group:team-security 19 | -------------------------------------------------------------------------------- /CODE_OF_CONDUCT.md: -------------------------------------------------------------------------------- 1 | # Contentful Community Code of Conduct 2 | 3 | The **Contentful Community** and the **Code of Conduct** governs all interactions with the contentful community. 4 | 5 | The **Contentful Community** is dedicated to providing a safe, inclusive, welcoming, and harassment-free space and experience for all community participants, regardless of gender identity and expression, sexual orientation, disability, physical appearance, socioeconomic status, body size, ethnicity, nationality, level of experience, age, religion (or lack thereof), or other identity markers. 6 | 7 | Our **Code of Conduct** exists because of that dedication, and we do not tolerate harassment in any form. See our full Code of Conduct and reporting guidelines at this [link](https://www.contentful.com/developers/code-of-conduct/). 8 | -------------------------------------------------------------------------------- /SECURITY.md: -------------------------------------------------------------------------------- 1 | ## Security Policy 2 | 3 | Security at Contentful 4 | 5 | Security being just important to us is a huge understatement. Security is a top priority at Contentful and we live it in our day-to-day activities. 6 | 7 | If you believe you have found a security vulnerability in any Contentful-owned repository, please report it to us as described below. 8 | 9 | ## Supported Versions 10 | 11 | Refer to individual repositories for supported versions. 12 | 13 | ## Reporting a Vulnerability 14 | 15 | Contentful engages with the community via our Responsible Disclosure Program, also known as our Bug Bounty Program. Our community plays an important role in helping us stay bug-free and secure. 16 | 17 | Found a vulnerability? Would you like to report a bug or something interesting that you found? The best way to reach out to us is via the submission form at the end of the [page](https://www.contentful.com/security/). 18 | 19 | Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue: 20 | 21 | * Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.) 22 | * Full paths of source file(s) related to the manifestation of the issue 23 | * The location of the affected source code (tag/branch/commit or direct URL) 24 | * Any special configuration required to reproduce the issue 25 | * Step-by-step instructions to reproduce the issue 26 | * Proof-of-concept or exploit code (if possible) 27 | * Impact of the issue, including how an attacker might exploit the issue 28 | 29 | This information will help us triage your report more quickly. 30 | 31 | Report security vulnerabilities in third-party modules to the person or team maintaining the module. 32 | 33 | 34 | --------------------------------------------------------------------------------