Skip to content

Licensing, code of conduct, and contributing guide - #205

Open
DZPM wants to merge 8 commits into
editionfrom
work/governance
Open

DZPM wants to merge 8 commits into
editionfrom
work/governance

Conversation

@DZPM

@DZPM DZPM commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

This one waits for the board, and it is the only pull request in this cleanup that does.

@mesejo: this is yours. Take it to the board, discuss it there, and approve it here when they are happy. There is no hurry. If anything is unclear or you disagree with any of it, tell me and we change it.

The rest of you are welcome to review, and please do, but for this one only Daniel's approval counts, and I will do the merge myself once it is there. That is a rule I am setting, not something GitHub enforces: the point is that we can look back later and see who signed it off.

It comes off edition and depends on nothing else: eight commits, nine files, +418 and -70 lines. It was written on top of #204 and retargeted once that stack settled, so an early reader may remember it showing #204's changes as well. It no longer does.

Why it needs a sign-off at all

The repository has no licence today, which means nobody has permission to reuse anything in it, not even to fork it. Choosing one is not a technical decision, and it says things on behalf of the association, so it should not be one person's call on a Tuesday.

The licence

LICENSE is MIT and covers the code: the templates, the stylesheets, the scripts, the workflows and the configuration.

LICENSING.md says the content is CC BY-SA 4.0, and lists what neither licence covers, with the reason for each: the photographs, the person pages, the sponsor logos, our own logos, the vendored libraries and the archived sites.

The reason for that last list is the part worth reading. We cannot license what we do not own. People sent us their own photograph and wrote their own text so that we would publish them here, and whoever did not want a photo did not send one. The copyright in a photograph belongs to whoever took it, and the permission we were given is to show it on this site, which is narrower than a CC licence, which would let a stranger reuse and adapt someone's face commercially and for ever. That permission can also be withdrawn, and a licence cannot.

The same goes for the text on a person's page: they wrote it.

The code of conduct

The text we already publish moves to CODE_OF_CONDUCT.md at the root, because that is where GitHub looks for it, and the page at /pybcn_association/coc/ now renders that file instead of holding its own copy. One text, two places, no chance of them drifting apart.

The last commit moves it from CC BY-SA 3.0 to 4.0, so the whole repository is on one version. Section 4(b)(ii) of the 3.0 licence allows it, and the credit to PyLadies and the mention of their 3.0 licence stay, because that same section requires it.

The contributing guide

CONTRIBUTING.md says how to open a pull request, which branch to target, how to add a person, a sponsor or an event without writing code, and what each check is for. GitHub shows it to whoever opens a pull request or an issue, which the README is not.

One thing to flag

.github/CODEOWNERS gains a rule for CODE_OF_CONDUCT.md. The text is moving out of content/pybcn_association/, which the web team owns, to the repository root, which nobody owned. Without the rule, our code of conduct could be edited with one ordinary approval.

What this does not do

It does not add a privacy policy or a legal notice. We publish 138 person pages and have neither, which matters more than this does. That is next, and it is a bigger conversation.

@DZPM DZPM self-assigned this Oct 7, 2026
@DZPM
DZPM force-pushed the pr/10-github-handles branch from 59906f8 to 14c88d9 Compare October 7, 2026 09:54
@DZPM DZPM closed this Oct 7, 2026
@DZPM
DZPM force-pushed the work/governance branch from b345566 to 14c88d9 Compare October 7, 2026 09:54
@DZPM DZPM reopened this Oct 7, 2026
@DZPM
DZPM requested a review from mesejo October 7, 2026 10:17
DZPM added 8 commits October 7, 2026 12:17
GitHub reads the code of conduct from CODE_OF_CONDUCT.md at the root of
the repository, never from the website, and the community profile counts
it as missing. The text was in content/pybcn_association/coc.md, which is
the published page.

A second copy at the root is two places for one legal text to drift
apart. The text moves to CODE_OF_CONDUCT.md, and the page now renders
that file through a new shortcode, repo-markdown, with os.ReadFile. The
front matter of the page stays, so the menu entry, the hero image and
the /coc alias do not change. The rendered page is byte identical to the
copy it replaces.

The shortcode checks the file name against an allowlist, so content
cannot read an arbitrary file of the repository into a page, and it
drops the leading H1, which the file carries so that it stands on its
own on GitHub.

The text leaves /content/pybcn_association/, which CODEOWNERS owns, for
the root, which it did not, so the file gets its own rule. It also
leaves content/, which is all that bin/check-html-safety scanned, so the
file joins the default scan.

The attribution to PyLadies and the CC BY-SA 3.0 notice stay at the end
of the text, which is what the share-alike clause requires.
GitHub links CONTRIBUTING.md from the issue and pull request forms, and
the community profile counts it as missing. The steps to make a change
were in the Collaborate section of the README, which a person opening a
pull request from the form does not see.

The section moves to CONTRIBUTING.md as it was, and the README points at
it, so there is one description of the process. A guide that is only a
link gets skipped, which is why the steps move and not a pointer. The
README keeps the detail of each check, which is for the people who
maintain them, and the guide links to those sections.

The Publishing process paragraph of the README still said to push new
commits to edition directly, which the Collaborate section and the
branch protection both contradicted. It points at the guide too.

The guide also says what the README did not: that the code of conduct
applies to contributions, that edition is the branch to target and
master holds the built site, how to add a person, a sponsor or an event
without writing code, and that a change to a path in CODEOWNERS waits
for a review from the web team, which the branch protection requires.
The code of conduct was adapted from the PyLadies one and carried its CC
BY-SA 3.0 Unported notice, so it was the one text in the repository on
a different version of the licence than the rest of the content, which
LICENSING.md puts under CC BY-SA 4.0. Two versions of one licence family
is one more thing for a reader to work out, for no gain.

The licence of the original permits the move. Section 4(b) of the CC
BY-SA 3.0 legal code says an Adaptation may be distributed under "(ii) a
later version of this License with the same License Elements as this
License", and the elements of both versions are Attribution and
ShareAlike. The same section requires the notices that refer to the
licence of the original to stay intact, so the file keeps the attribution
to PyLadies and the mention of CC BY-SA 3.0, and adds the 4.0 licence it
is now under. The text of the code of conduct itself does not change.

LICENSING.md moves the file from the paths no licence covers to the
content under CC BY-SA 4.0, and says which clause allows it. The README
sentence that said the file keeps 3.0 goes with it.
These documents were written on a branch that had moved further than
edition: it had the people and sponsor fields documented in the README,
a data/ directory and assets/xsl/. On edition none of those exist yet.

LICENSING no longer lists assets/xsl/ or data/ under the MIT licence,
because there is nothing there to license. The contributing guide
describes the person fields instead of linking to a README section that
does not exist on this branch, and keeps the links that do resolve.

Checked: every path LICENSING names exists, and every README anchor the
guide links to resolves.
@DZPM
DZPM force-pushed the work/governance branch from 2183e6d to 6fc2dbc Compare October 7, 2026 10:19
@DZPM
DZPM changed the base branch from pr/10-github-handles to edition October 7, 2026 10:19
@DZPM
DZPM marked this pull request as ready for review October 8, 2026 09:09
@DZPM
DZPM requested a review from a team as a code owner October 8, 2026 09:09
@DZPM DZPM assigned mesejo and unassigned DZPM Oct 8, 2026
Comment thread CONTRIBUTING.md
bin/hugo --minify -D -d public && bin/check-rendered
```

Pillow is only needed for the black and white photo check. Without it the

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this be updated after the merge of #206? After all, Pillow is needed for the fit-sources script

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants