CipherBoard contributors and maintainers are expected to make technical collaboration safe, respectful, and useful. English and Russian participation are equally welcome. Disagreement about architecture, cryptography, risk, or evidence is normal; personal attacks are not.
Examples of constructive behavior include:
- discussing claims with reproducible evidence and clearly stated assumptions;
- giving specific, actionable review feedback;
- respecting different experience levels, languages, identities, and threat models;
- accepting correction and updating conclusions when evidence changes;
- protecting security reporters and user privacy; and
- keeping public discussions free of real secrets and unpatched vulnerability details.
Unacceptable behavior includes:
- harassment, threats, discrimination, sexualized attention, or targeted intimidation;
- insults, personal attacks, deliberate humiliation, or sustained disruption;
- publishing another person's private information or security-sensitive data;
- pressuring a reporter to disclose an unpatched vulnerability publicly;
- knowingly making false security claims or impersonating CipherBoard, HeliBoard, maintainers, or reviewers; and
- retaliation against a person who reports a safety or conduct concern in good faith.
This standard applies in repository issues, pull requests, code review, discussions, release coordination, and other project spaces. It also applies when someone publicly represents the project.
Maintainers may edit or remove comments, close or lock threads, reject contributions, issue warnings, or temporarily or permanently restrict participation when behavior violates this policy. Enforcement should be proportionate, consistent, and avoid exposing reporters or affected people.
Report abusive GitHub content using GitHub's private reporting and blocking tools. For a project-specific concern, contact maintainers through a private channel exposed by the repository when possible. If no private channel is available, open a minimal issue requesting contact without including personal, security, or incident details.
Security vulnerabilities must follow SECURITY.md, not the
conduct-reporting path.
Участники проекта должны общаться уважительно, обсуждать технические решения на
основе проверяемых фактов и не публиковать чужие персональные данные, секреты или
детали неисправленной уязвимости. Оскорбления, угрозы, дискриминация, травля,
выдача себя за представителей проекта и преследование добросовестных
исследователей недопустимы. Для сообщения об уязвимости используйте
SECURITY.md.