HeaderProof is a technical open-source project. Participation is expected to stay respectful, evidence-based, and focused on improving the project.
- Critique code, evidence, and design decisions rather than people.
- Give contributors room to ask questions and make mistakes.
- Keep reviews specific and actionable.
- Respect project safety boundaries and coordinated disclosure.
- Do not publish credentials, private target data, or undisclosed third-party vulnerability details.
Harassment, threats, discriminatory attacks, deliberate disruption, spam, doxxing, and repeated bad-faith interaction are not accepted.
Maintainers may edit or remove content, lock conversations, reject contributions, or restrict participation when necessary to protect the project and its community. Decisions should be based on observable behavior and applied consistently.
For content that violates GitHub-wide policies, use GitHub's reporting tools. Security vulnerabilities in HeaderProof itself belong in private vulnerability reporting, not conduct reports.
This code applies to HeaderProof repository spaces, including issues, pull requests, reviews, and Discussions.