Threat Model Reviewer

Code of Conduct

Public repository documentation · View source on GitHub

On this page

Our commitment

This project exists to help teams ship safer systems. Everyone who takes part — filing an issue, proposing a change, or answering a question — should be able to do so without harassment or hostility, regardless of experience level, background, identity or affiliation.

Expected behaviour

  • Be respectful and assume good intent.
  • Critique ideas, designs and code — not people.
  • Accept that reviewers may decline a change, and explain decisions with reasons.
  • Respect confidentiality: threat models describe real attack surfaces. Never post another organization's model, and sanitize your own before sharing.

Unacceptable behaviour

  • Harassment, personal attacks, discriminatory or demeaning language.
  • Publishing others' private information without explicit permission.
  • Deliberately disruptive conduct, or persistent unwelcome contact.
  • Using this project to develop or distribute offensive tooling, or to attack systems you are not authorized to test. This is a defensive security tool.

Scope

This applies in all project spaces — issues, pull requests, discussions and releases — and when representing the project in public.

Reporting

Report concerns privately to the maintainer via GitHub, or through the private reporting channel described in SECURITY.md if the matter is sensitive. Reports are handled confidentially and reviewed as promptly as reasonably possible.

Maintainers may edit or remove contributions, and may restrict participation, when conduct breaks these expectations.

Attribution

These guidelines are informed by the Contributor Covenant, version 2.1, which is available under CC BY 4.0.