Skip to content

Status: approved design, pending rollout — the governance framework below is adopted for Community Edition repositories entering public release. Contribution and support channels described here go live with the phased public rollout; until a channel is explicitly listed as operational on this page, treat it as pending.

Project Governance

Xtrape's open-source governance rests on five principles:

  1. Licensing, trademark, contribution, security reporting, and support terms are separate concerns — none is inferred from another.
  2. Public contributors must be able to participate without internal infrastructure access.
  3. Community support stays distinct from paid or hosted commitments.
  4. Security reports need a private path and must never require production secrets.
  5. A merge is not a release. Publication is a separate, deliberate act.

License

All public Community Edition repositories and Xtrape-owned source packages are licensed under the Apache License 2.0, with the unmodified license text in each repository root. Copyright: The Xtrape Project and contributors — contributors retain their copyright. Published packages, images, and archives expose their source license, notices, source repository, and release tag/commit.

Trademark

The license and the marks are deliberately decoupled: Apache-2.0 grants no rights to Xtrape names or logos, which are reserved by The Xtrape Project. Descriptive and nominative use is normally fine — "compatible with Xtrape", "an integration for Xtrape", "based on Xtrape Community Edition", "forked from the Xtrape project". Materially modified distributions and independent hosted services need their own primary name and must not present as official or use confusingly similar product, domain, package-scope, or store identities.

Contributing

Current phase: issues and patches, not pull requests. External pull requests are not accepted yet — a deliberate staging decision, stated plainly so nobody builds changes that cannot be taken. Contributions arrive as a description plus a git format-patch patch (or a link to a fork branch) sent to the project role address; a maintainer applies it preserving authorship and sign-off.

  • Legal instrument: Developer Certificate of Origin 1.1 (git commit -s). No CLA.
  • Material AI assistance must be disclosed: affected areas, human validation performed, tests actually run, known limitations. The human contributor remains responsible.
  • Publishing and deployment stay separate: the public host never reaches internal servers, contributors never gain deployment access, and fork builds never receive secrets.

Whether and how external pull requests open is a scheduled evaluation later in the current release train.

Security

Report suspected vulnerabilities privately — never as a public issue. See SECURITY in the repository for the current intake address and expectations. Operational targets (not SLAs): acknowledgement within 3 business days, initial triage within 7 calendar days. Coordinated disclosure is preferred, with a stated safe-harbor intent for good-faith research.

Code of conduct

The project adopts the Contributor Covenant 2.1 as its baseline. Conduct reports go to a private moderation channel or the role address, never a public issue. Enforcement is proportionate and distinguishes good-faith technical disagreement from abusive conduct.

Support expectations

Community Edition is best effort: no guaranteed response time, resolution time, maintenance duration, or SLA. Security fixes and ordinary documentation are never withheld to force commercial engagement. Paid support, hosted-service commitments, and contractual SLAs are separate offerings and must not be inferred from CE repositories. Pre-1.0 users should pin exact versions and digests.

Document status legend

See Status legend for how stable / experimental / working-draft markings are applied across this site.

Site content and code released under Apache-2.0. "Xtrape" is a trademark of The Xtrape Project.