Skip to content

Commit c9dcf39

Browse files
Merge pull request #236 from syncfusion/UpdatePolicy
Security policy and code of conduct updated
2 parents 8ef1f6a + d7c8650 commit c9dcf39

File tree

2 files changed

+104
-0
lines changed

2 files changed

+104
-0
lines changed

.github/CODE_OF_CONDUCT.md

Lines changed: 71 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,71 @@
1+
# Syncfusion Code of Conduct and Corporate Ethics Policy
2+
3+
## 1. Purpose
4+
5+
Syncfusion is committed to responsible corporate citizenship. Our commitment to integrity begins with following all local, state, and federal laws and regulations.
6+
7+
Employment at Syncfusion is based exclusively on individual merit and qualifications. The company prohibits discrimination on the basis of race, color, religion, veteran status, national origin, ancestry, pregnancy status, sex, gender identity or expression, age, marital status, mental or physical disability, medical condition, sexual orientation, or any other characteristic protected by law.
8+
9+
Syncfusion will not tolerate discrimination, harassment, or bullying in any form and will not retaliate against any employee who reports or participates in an investigation of such behavior.
10+
11+
## 2. Standards
12+
13+
Syncfusion complies with all laws relating to minimum wage and overtime payments. Employees must record their time accurately in accordance with the company’s established procedures.
14+
15+
The company adheres to all laws prohibiting child labor, slave labor, and other illegal workplace practices.
16+
17+
Syncfusion believes that acting ethically and responsibly is not just the right thing to do—it is also good for business and crucial for our continued success. We are dedicated to full compliance with all applicable laws and to maintaining high ethical standards in all business transactions.
18+
19+
## 3. Commitment to Ethics
20+
21+
Syncfusion is committed to protecting employees, customers, partners, vendors, and the company from illegal or damaging actions by individuals, knowingly or unknowingly. This policy establishes behavioral and ethical standards for Syncfusion’s employees, vendors, and the company.
22+
23+
This policy also aligns with the community standards of open-source initiatives maintained by Syncfusion, including the Syncfusion .NET MAUI Toolkit.
24+
25+
### 3.1 Executive Commitment to Ethics
26+
27+
Executives must:
28+
- Maintain an open-door policy and welcome suggestions or concerns.
29+
- Disclose any conflicts of interest regarding their position within Syncfusion.
30+
31+
### 3.2 Employee Commitment to Ethics
32+
33+
Syncfusion employees shall:
34+
- Treat everyone fairly and respectfully.
35+
- Promote a team environment and avoid unethical or compromising practices.
36+
- Abide by Syncfusion’s mission, values, and policies.
37+
- Avoid dishonesty, fraud, or misrepresentation.
38+
- Comply with all legal regulations and standards of equity.
39+
- Respect diversity and differences in people.
40+
- Refrain from profanity, abuse, or violence.
41+
- Maintain confidentiality during and after employment.
42+
- Respect and abide by management decisions.
43+
- Avoid public criticism that could harm Syncfusion’s reputation.
44+
45+
### 3.3 Maintaining Ethical Practices
46+
47+
Every employee must:
48+
- Support ethical behavior consistently.
49+
- Notify supervisors of any actual or potential conflicts of interest.
50+
- Avoid prohibited activities, including:
51+
- Using their position for personal or family gain.
52+
- Accepting or offering gifts or preferential treatment.
53+
- Misusing Syncfusion’s assets or resources.
54+
55+
### 3.4 Unethical Behavior
56+
57+
Unethical or illegal practices are strictly prohibited, including:
58+
- Corruption, bribery, or misuse of proprietary information.
59+
- Unauthorized use of company assets or confidential relationships.
60+
- Abuse of employment benefits.
61+
62+
All violations must be reported to: **[email protected]**
63+
64+
## 4. Open Source Contribution Ethics – MAUI Toolkit
65+
66+
Syncfusion maintains high ethical and community standards for its open-source projects. Contributors and users of the Syncfusion .NET MAUI Toolkit are expected to adhere to its [Code of Conduct](https://github.com/syncfusion/maui-toolkit) harassment-free collaboration environment.
67+
68+
Anyone participating in the open-source community representing Syncfusion should:
69+
- Follow the same integrity and professionalism expected of internal employees.
70+
- Avoid discriminatory or abusive behavior in any form.
71+
- Promote transparency and respect among all contributors, users, and maintainers.

.github/SECURITY.md

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
# Security Policy
2+
3+
## 1. Purpose
4+
5+
We prioritize our project’s security and encourage the community to responsibly report any vulnerabilities.
6+
7+
## 2. Reporting a Vulnerability
8+
9+
We take the security of our Syncfusion .NET MAUI Toolkit project very seriously. If you discover a security vulnerability, please report it responsibly using the steps outlined below.
10+
11+
### 2.1 How to Report
12+
13+
#### 2.1.1 Contact us privately:
14+
- Please email us at **[email protected]** with a detailed report of the vulnerability.
15+
- Wait until we verify that the problem has been fixed before making the announcement in public.
16+
17+
#### 2.1.2 Provide details:
18+
- Provide instructions on how to replicate the vulnerability.
19+
- Share any possible impact or exploitation scenarios.
20+
21+
#### 2.1.3 Expect a response:
22+
- We will acknowledge receipt of your report within **2 business days**.
23+
- You will receive updates on the progress as we investigate and resolve the issue.
24+
25+
## 3. Security Patch Process
26+
27+
### 3.1 After a vulnerability is reported and verified:
28+
- We will assess its severity and impact.
29+
- A fix will be developed and tested internally.
30+
31+
The resolution will be included in the next available release. If necessary, a security patch will be issued immediately.
32+
33+
Affected users will be notified in the GitHub repository's **Releases** page and other relevant channels.

0 commit comments

Comments
 (0)