The DevSec Blueprint community exists to help people become better security engineers. Everyone participating in this repository — issues, pull requests, reviews, and Discord discussion about this work — is expected to make that easier, not harder.
Expected:
- Critique the engineering, not the person.
- Assume the other person has context you do not.
- Accept that "you are right, I was wrong" is a normal and respected outcome.
- Be patient with people learning this material. That is who DSB is for.
Not accepted:
- Harassment, personal attacks, or demeaning comments of any kind.
- Discrimination based on identity or background.
- Publishing others' private information without permission.
- Sustained disruption of technical discussion.
This project reviews security tooling, and vendor advocacy is a recurring source of friction. Arguing that a product is technically the best fit for a capability is legitimate engineering. Pushing to make a specific vendor a DSB requirement is out of scope by design — see CONTRIBUTING.md — and pressing it after a maintainer decision is a conduct problem, not a technical one.
Applies in all project spaces and when representing the project publicly.
Report conduct concerns to the maintainers through the DSB Discord. Do not open a public issue.
Reports are handled confidentially. Maintainers may warn, remove contributions, or ban participants, and will explain the decision to the person affected where doing so does not expose a reporter.
Maintainers who violate this policy are held to it more strictly, not less.