diff --git a/CHANGELOG.md b/CHANGELOG.md index 6295bdf..5adb420 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Change Log +## [v1.0.2] - 20203-12-15 + +Security Fixes: +- Fix vulnerabilities in go:1.19.12 CVE-2023-39321, CVE-2023-39322, CVE-2023-39318, CVE-2023-39319. +- Release with new license - MIT + ## [v1.0.1] - 20203-07-07 Make Password Safe Terraform Provider available in the Public Terraform Registry [published here](https://registry.terraform.io/providers/BeyondTrust/passwordsafe/1.0.1). diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..ba39412 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,122 @@ +# Code of Conduct +## Our Pledge +We as members, contributors, and leaders pledge to make participation in our +community a harassment-free experience for everyone, regardless of age, body +size, visible or invisible disability, ethnicity, sex characteristics, gender +identity and expression, level of experience, education, socio-economic status, +nationality, personal appearance, race, caste, color, religion, or sexual +identity and orientation. + +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards +Examples of behavior that contributes to a positive environment for our +community include: + +Demonstrating empathy and kindness toward other people + +Being respectful of differing opinions, viewpoints, and experiences + +Giving and gracefully accepting constructive feedback + +Accepting responsibility and apologizing to those affected by our mistakes, +and learning from the experience + +Focusing on what is best not just for us as individuals, but for the overall +community + +Examples of unacceptable behavior include: + +The use of sexualized language or imagery, and sexual attention or advances of +any kind + +Trolling, insulting or derogatory comments, and personal or political attacks + +Public or private harassment + +Publishing others' private information, such as a physical or email address, +without their explicit permission + +Other conduct which could reasonably be considered inappropriate in a +professional setting + +## Enforcement Responsibilities +Community leaders are responsible for clarifying and enforcing our standards of +acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, offensive, +or harmful. + +Community leaders have the right and responsibility to remove, edit, or reject +comments, commits, code, wiki edits, issues, and other contributions that are +not aligned to this Code of Conduct, and will communicate reasons for moderation +decisions when appropriate. + +## Scope +This Code of Conduct applies within all community spaces, and also applies when +an individual is officially representing the community in public spaces. +Examples of representing our community include using an official e-mail address, +posting via an official social media account, or acting as an appointed +representative at an online or offline event. + +## Enforcement +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the community leaders responsible for enforcement at +[INSERT CONTACT METHOD]. +All complaints will be reviewed and investigated promptly and fairly. + +All community leaders are obligated to respect the privacy and security of the +reporter of any incident. + +## Enforcement Guidelines +Community leaders will follow these Community Impact Guidelines in determining +the consequences for any action they deem in violation of this Code of Conduct: + +### 1. Correction +`Community Impact`: Use of inappropriate language or other behavior deemed +unprofessional or unwelcome in the community. + +`Consequence`: A private, written warning from community leaders, providing +clarity around the nature of the violation and an explanation of why the +behavior was inappropriate. A public apology may be requested. + +### 2. Warning +`Community Impact`: A violation through a single incident or series of +actions. + +`Consequence`: A warning with consequences for continued behavior. No +interaction with the people involved, including unsolicited interaction with +those enforcing the Code of Conduct, for a specified period of time. This +includes avoiding interactions in community spaces as well as external channels +like social media. Violating these terms may lead to a temporary or permanent +ban. + +### 3. Temporary Ban +`Community Impact`: A serious violation of community standards, including +sustained inappropriate behavior. + +`Consequence`: A temporary ban from any sort of interaction or public +communication with the community for a specified period of time. No public or +private interaction with the people involved, including unsolicited interaction +with those enforcing the Code of Conduct, is allowed during this period. +Violating these terms may lead to a permanent ban. + +### 4. Permanent Ban +`Community Impact`: Demonstrating a pattern of violation of community +standards, including sustained inappropriate behavior, harassment of an +individual, or aggression toward or disparagement of classes of individuals. + +`Consequence`: A permanent ban from any sort of public interaction within the +community. + +## Attribution +This Code of Conduct is adapted from the Contributor Covenant, +version 2.1, available at +[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1]. + +Community Impact Guidelines were inspired by +Mozilla's code of conduct enforcement ladder. + +For answers to common questions about this code of conduct, see the FAQ at +[https://www.contributor-covenant.org/faq][FAQ]. Translations are available at +[https://www.contributor-covenant.org/translations][translations]. \ No newline at end of file diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..4b52457 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,32 @@ +# Contributing to the BeyondTrust Password Safe Terraform Provider + +Thank you for your interest in contributing to our project! + +Here is some information on how to get started and where to ask for help. + +## Getting Started + +The Password Safe Terraform provider is a Terraform integration for Password Safe which enables using Password Safe secrets management capabilities with Terraform. + +## How can I Contribute? + +### Reporting Bugs + +Bugs should be submitted through BeyondTrust Support. Any bugs should be submitted against _Password Safe Support_. Our support team will ensure the escalation is raised to the proper team internally. + +If the bug is a security vulnerability, instead please refer to the [responsible disclosure section of our security policy](https://www.beyondtrust.com/security#disclosure). + +### Feature Requests + +Feature requests should also be submitted through BeyondTrust Support, also against _Password Safe Support_. Submitting through our support organization will ensure the request gets send to the proper Product Management team for consideration. + +### Suggesting a Code Change + +#### **Did you write a patch that fixes a bug?** + +- Submitted through BeyondTrust Support. +- Ensure you describe clearly both the problem and the solution. + +#### **Do you have ideas for a new feature or change an existing one?** + +- Consider submitting a feature request through BeyondTrust Support to ensure that your proposed changes do not conflict with new features that are already planned or in development.