From de7cebc96687f78347c251181abcb02764301062 Mon Sep 17 00:00:00 2001 From: Jeffrey Parker Date: Fri, 2 Oct 2026 09:41:14 -0400 Subject: [PATCH 1/2] docs: align community files with Cisco open source standards --- CODE_OF_CONDUCT.md | 132 +++++++++++++++++++++++++++++++++++++++++++++ CONTRIBUTING.md | 56 +++++++++++++++++++ README.md | 4 +- SECURITY.md | 57 ++++++++++++++++++-- 4 files changed, 242 insertions(+), 7 deletions(-) create mode 100644 CODE_OF_CONDUCT.md create mode 100644 CONTRIBUTING.md diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..2adce43 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,132 @@ +# Contributor Covenant Code of Conduct + +## Our Pledge + +We as members, contributors, and leaders pledge to make participation in our +community a harassment-free experience for everyone, regardless of age, body +size, visible or invisible disability, ethnicity, sex characteristics, gender +identity and expression, level of experience, education, socio-economic status, +nationality, personal appearance, race, caste, color, religion, or sexual +identity and orientation. + +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards + +Examples of behavior that contributes to a positive environment for our +community include: + +* Demonstrating empathy and kindness toward other people +* Being respectful of differing opinions, viewpoints, and experiences +* Giving and gracefully accepting constructive feedback +* Accepting responsibility and apologizing to those affected by our mistakes, + and learning from the experience +* Focusing on what is best not just for us as individuals, but for the overall + community + +Examples of unacceptable behavior include: + +* The use of sexualized language or imagery, and sexual attention or advances of + any kind +* Trolling, insulting or derogatory comments, and personal or political attacks +* Public or private harassment +* Publishing others' private information, such as a physical or email address, + without their explicit permission +* Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Enforcement Responsibilities + +Community leaders are responsible for clarifying and enforcing our standards of +acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, offensive, +or harmful. + +Community leaders have the right and responsibility to remove, edit, or reject +comments, commits, code, wiki edits, issues, and other contributions that are +not aligned to this Code of Conduct, and will communicate reasons for moderation +decisions when appropriate. + +## Scope + +This Code of Conduct applies within all community spaces, and also applies when +an individual is officially representing the community in public spaces. +Examples of representing our community include using an official email address, +posting via an official social media account, or acting as an appointed +representative at an online or offline event. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the community leaders responsible for enforcement at +[oss-conduct@cisco.com](mailto:oss-conduct@cisco.com). All complaints will be +reviewed and investigated promptly and fairly. + +All community leaders are obligated to respect the privacy and security of the +reporter of any incident. + +## Enforcement Guidelines + +Community leaders will follow these Community Impact Guidelines in determining +the consequences for any action they deem in violation of this Code of Conduct: + +### 1. Correction + +**Community Impact**: Use of inappropriate language or other behavior deemed +unprofessional or unwelcome in the community. + +**Consequence**: A private, written warning from community leaders, providing +clarity around the nature of the violation and an explanation of why the +behavior was inappropriate. A public apology may be requested. + +### 2. Warning + +**Community Impact**: A violation through a single incident or series of +actions. + +**Consequence**: A warning with consequences for continued behavior. No +interaction with the people involved, including unsolicited interaction with +those enforcing the Code of Conduct, for a specified period of time. This +includes avoiding interactions in community spaces as well as external channels +like social media. Violating these terms may lead to a temporary or permanent +ban. + +### 3. Temporary Ban + +**Community Impact**: A serious violation of community standards, including +sustained inappropriate behavior. + +**Consequence**: A temporary ban from any sort of interaction or public +communication with the community for a specified period of time. No public or +private interaction with the people involved, including unsolicited interaction +with those enforcing the Code of Conduct, is allowed during this period. +Violating these terms may lead to a permanent ban. + +### 4. Permanent Ban + +**Community Impact**: Demonstrating a pattern of violation of community +standards, including sustained inappropriate behavior, harassment of an +individual, or aggression toward or disparagement of classes of individuals. + +**Consequence**: A permanent ban from any sort of public interaction within the +community. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], +version 2.1, available at +[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1]. + +Community Impact Guidelines were inspired by [Mozilla's code of conduct +enforcement ladder][Mozilla CoC]. + +For answers to common questions about this code of conduct, see the FAQ at +[https://www.contributor-covenant.org/faq][FAQ]. Translations are available at +[https://www.contributor-covenant.org/translations][translations]. + +[homepage]: https://www.contributor-covenant.org +[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html +[Mozilla CoC]: https://github.com/mozilla/diversity +[FAQ]: https://www.contributor-covenant.org/faq +[translations]: https://www.contributor-covenant.org/translations diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..34feef8 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,56 @@ +# How to Contribute + +Thanks for your interest in contributing to Duo Universal Python SDK! Here are a +few general guidelines on contributing and reporting bugs that we ask you to +review. Following these guidelines helps to communicate that you respect the +time of the contributors managing and developing this open source project. In +return, they should reciprocate that respect in addressing your issue, assessing +changes, and helping you finalize your pull requests. In that spirit of mutual +respect, we endeavor to review incoming issues and pull requests within 10 days, +and will close any lingering issues or pull requests after 60 days of +inactivity. + +Please note that all of your interactions in the project are subject to our +[Code of Conduct](/CODE_OF_CONDUCT.md). This includes creation of issues or pull +requests, commenting on issues or pull requests, and extends to all interactions +in any real-time space e.g., Slack, Discord, etc. + +## Reporting Issues + +Before reporting a new issue, please ensure that the issue was not already +reported or fixed by searching through our [issues +list](https://github.com/duosecurity/duo_universal_python/issues). + +When creating a new issue, please be sure to include a **title and clear +description**, as much relevant information as possible, and, if possible, a +test case. + +**If you discover a security bug, please do not report it through GitHub. +Instead, please see security procedures in [SECURITY.md](/SECURITY.md).** + +## Sending Pull Requests + +Before sending a new pull request, take a look at existing pull requests and +issues to see if the proposed change or fix has been discussed in the past, or +if the change was already implemented but not yet released. + +We expect new pull requests to include tests for any affected behavior, and, as +we follow semantic versioning, we may reserve breaking changes until the next +major version release. + +## Other Ways to Contribute + +We welcome anyone who wants to contribute to Duo Universal Python SDK to triage +and reply to open issues to help troubleshoot and fix existing bugs. Here is +what you can do: + +- Help ensure that existing issues follow the recommendations from the + _[Reporting Issues](#reporting-issues)_ section, providing feedback to the + issue's author on what might be missing. +- Review existing pull requests, and testing patches against real existing + applications that use Duo Universal Python SDK. +- Write a test, or add a missing test case to an existing test. + +Thanks again for your interest in contributing to Duo Universal Python SDK! + +:heart: diff --git a/README.md b/README.md index 33e1fe3..227e4a7 100644 --- a/README.md +++ b/README.md @@ -4,7 +4,7 @@ [![Issues](https://img.shields.io/github/issues/duosecurity/duo_universal_python)](https://github.com/duosecurity/duo_universal_python/issues) [![Forks](https://img.shields.io/github/forks/duosecurity/duo_universal_python)](https://github.com/duosecurity/duo_universal_python/network/members) [![Stars](https://img.shields.io/github/stars/duosecurity/duo_universal_python)](https://github.com/duosecurity/duo_universal_python/stargazers) -[![License](https://img.shields.io/badge/License-View%20License-orange)](https://github.com/duosecurity/duo_universal_python/blob/master/LICENSE) +[![License](https://img.shields.io/badge/License-View%20License-orange)](https://github.com/duosecurity/duo_universal_python/blob/main/LICENSE) This SDK allows a web developer to quickly add Duo's interactive, self-service, two-factor authentication to any Python3 web login form. Only Python 3 is supported. @@ -33,7 +33,7 @@ pip3 install duo_universal Once it's installed, see our developer documentation at https://duo.com/docs/duoweb and `demo/app.py` in this repo for guidance on integrating Duo 2FA into your web application. ## Contribute -To contribute, fork this repo and make a pull request with your changes when they're ready. +To contribute, fork this repo and make a pull request with your changes when they're ready. See [CONTRIBUTING.md](https://github.com/duosecurity/duo_universal_python/blob/main/CONTRIBUTING.md) for guidelines and our [Code of Conduct](https://github.com/duosecurity/duo_universal_python/blob/main/CODE_OF_CONDUCT.md). If you're not already working from a dedicated development environment, it's recommended a virtual environment is used. Assuming a virtual environment named `env`, create and activate the environment: ``` diff --git a/SECURITY.md b/SECURITY.md index 16c9604..0c6ca6c 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,8 +1,55 @@ -Duo is committed to providing secure software to all our customers and users. We take all security concerns seriously and ask that any disclosures be handled responsibly. +# Security Policies and Procedures -# Security Policy +This document outlines security procedures and general policies for the +Duo Universal Python SDK project. -## Reporting a Vulnerability -**Please do not use Github issues or pull requests to report security vulnerabilities.** +- [Disclosing a security issue](#disclosing-a-security-issue) +- [Vulnerability management](#vulnerability-management) +- [Suggesting changes](#suggesting-changes) -If you believe you have found a security vulnerability in Duo software, please follow our response process described at https://duo.com/support/security-and-reliability/security-response. +## Disclosing a security issue + +The Duo Universal Python SDK maintainers take all security issues in the project +seriously. Thank you for improving the security of Duo Universal Python SDK. We +appreciate your dedication to responsible disclosure and will make every effort +to acknowledge your contributions. + +To report a vulnerability, please email the [Cisco Open security contact +email](mailto:oss-security@cisco.com). + +Here are some helpful details to include in your report: + +- a detailed description of the issue +- the steps required to reproduce the issue +- versions of the project that may be affected by the issue +- if known, any mitigations for the issue + +A maintainer will acknowledge the report within three (3) business days, and +will send a more detailed response within an additional three (3) business days +indicating the next steps in handling your report. + +If you have not received a response during the allotted response window, please +reach out via the [Cisco Open security contact +email](mailto:oss-security@cisco.com). + +After the initial reply to your report, the maintainers will endeavor to keep +you informed of the progress towards a fix and full announcement, and may ask +for additional information or guidance. + +## Vulnerability management + +When the maintainers receive a disclosure report, they will assign it to a +primary handler. + +This person will coordinate the fix and release process, which involves the +following steps: + +- confirming the issue +- determining affected versions of the project +- auditing code to find any potential similar problems +- preparing fixes for all releases under maintenance + +## Suggesting changes + +If you have suggestions on how this process could be improved please submit an +issue or pull request. From 6ae99d660eeed7b59cbcd64c157bb91e7e3e8705 Mon Sep 17 00:00:00 2001 From: Jeffrey Parker Date: Fri, 2 Oct 2026 10:38:35 -0400 Subject: [PATCH 2/2] docs: show the security contact address in SECURITY.md --- SECURITY.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 0c6ca6c..be244ee 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -14,8 +14,8 @@ seriously. Thank you for improving the security of Duo Universal Python SDK. We appreciate your dedication to responsible disclosure and will make every effort to acknowledge your contributions. -To report a vulnerability, please email the [Cisco Open security contact -email](mailto:oss-security@cisco.com). +To report a vulnerability, please email the Cisco Open security contact at +[oss-security@cisco.com](mailto:oss-security@cisco.com). Here are some helpful details to include in your report: @@ -29,8 +29,8 @@ will send a more detailed response within an additional three (3) business days indicating the next steps in handling your report. If you have not received a response during the allotted response window, please -reach out via the [Cisco Open security contact -email](mailto:oss-security@cisco.com). +reach out via the Cisco Open security contact at +[oss-security@cisco.com](mailto:oss-security@cisco.com). After the initial reply to your report, the maintainers will endeavor to keep you informed of the progress towards a fix and full announcement, and may ask