Skip to content

Commit 653b18a

Browse files
Antony BaileyAntony Bailey
authored andcommitted
nice bits
1 parent 50599ac commit 653b18a

File tree

2 files changed

+120
-0
lines changed

2 files changed

+120
-0
lines changed

CODE_OF_CONDUCT.md

Lines changed: 70 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,70 @@
1+
# Code of Conduct
2+
3+
## Our Pledge
4+
5+
We as members, contributors, and leaders pledge to make participation in our
6+
community a harassment-free experience for everyone, regardless of age, body
7+
size, visible or invisible disability, ethnicity, sex characteristics, gender
8+
identity and expression, level of experience, education, socio-economic status,
9+
nationality, personal appearance, race, religion, or sexual identity
10+
and orientation.
11+
12+
We pledge to act and interact in ways that contribute to an open, welcoming,
13+
diverse, inclusive, and healthy community.
14+
15+
## Our Standards
16+
17+
Examples of behavior that contributes to a positive environment for our
18+
community include:
19+
20+
* Demonstrating empathy and kindness toward other people
21+
* Being respectful of differing opinions, viewpoints, and experiences
22+
* Giving and gracefully accepting constructive feedback
23+
* Accepting responsibility and apologizing to those affected by our mistakes,
24+
and learning from the experience
25+
* Focusing on what is best not just for us as individuals, but for the
26+
overall community
27+
28+
Examples of unacceptable behavior include:
29+
30+
* The use of sexualized language or imagery, and sexual attention or
31+
advances of any kind
32+
* Trolling, insulting or derogatory comments, and personal or political attacks
33+
* Public or private harassment
34+
* Publishing others' private information, such as a physical or email
35+
address, without their explicit permission
36+
* Other conduct which could reasonably be considered inappropriate in a
37+
professional setting
38+
39+
## Enforcement Responsibilities
40+
41+
Project maintainers are responsible for clarifying and enforcing our standards of
42+
acceptable behavior and will take appropriate and fair corrective action in
43+
response to any behavior that they deem inappropriate, threatening, offensive,
44+
or harmful.
45+
46+
## Scope
47+
48+
This Code of Conduct applies within all community spaces, and also applies when
49+
an individual is officially representing the community in public spaces.
50+
Examples of representing our community include using an official e-mail address,
51+
posting via an official social media account, or acting as an appointed
52+
representative at an online or offline event.
53+
54+
## Enforcement
55+
56+
Instances of abusive, harassing, or otherwise unacceptable behavior may be
57+
reported to the project maintainers responsible for enforcement at
58+
support@antonybailey.net. All complaints will be reviewed and investigated
59+
promptly and fairly.
60+
61+
All project maintainers are obligated to respect the privacy and security of the
62+
reporter of any incident.
63+
64+
## Attribution
65+
66+
This Code of Conduct is adapted from the [Contributor Covenant][homepage],
67+
version 2.0, available at
68+
https://www.contributor-covenant.org/version/2/0/code_of_conduct.html.
69+
70+
[homepage]: https://www.contributor-covenant.org

SECURITY.md

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
# Security Policy
2+
3+
## Supported Versions
4+
5+
Use this section to tell people about which versions of your project are
6+
currently being supported with security updates.
7+
8+
| Version | Supported |
9+
| ------- | ------------------ |
10+
| 0.1.x | :white_check_mark: |
11+
12+
## Reporting a Vulnerability
13+
14+
The pySQLY team takes security issues seriously. We appreciate your efforts
15+
to responsibly disclose your findings and will make every effort to acknowledge
16+
your contributions.
17+
18+
To report a security issue, please email support@antonybailey.net with a
19+
description of the issue, the steps you took to create the issue, affected
20+
versions, and if known, mitigations for the issue.
21+
22+
We aim to respond to security reports within 48 hours. If for some reason you
23+
don't get a response within that timeframe, please follow up via email to ensure
24+
we received your original message.
25+
26+
After the initial reply to your report, the security team will keep you informed
27+
of the progress towards a fix and full announcement, and may ask for additional
28+
information or guidance.
29+
30+
## Security Best Practices for Using pySQLY
31+
32+
When using pySQLY in your applications, consider these security best practices:
33+
34+
1. **Always sanitize user inputs**: While pySQLY helps prevent SQL injection by
35+
using parameterized queries, it's still important to validate and sanitize all
36+
user inputs before processing them.
37+
38+
2. **Use principle of least privilege**: Configure your database users with
39+
the minimum required permissions for your application to function.
40+
41+
3. **Keep dependencies updated**: Regularly update pySQLY and its dependencies
42+
to ensure you have the latest security patches.
43+
44+
4. **Store connection strings securely**: Never hard-code database credentials in
45+
your source code. Use environment variables or a secure secret management system.
46+
47+
5. **Log responsibly**: Be careful not to log sensitive information like queries
48+
that might contain personal data or credentials.
49+
50+
Thank you for helping keep pySQLY and its community safe!

0 commit comments

Comments
 (0)