Skip to content

Commit 556de65

Browse files
authored
docs(ospo): community health rollout v2 — README, agents.md, health files (#59)
Introduced by the Kiteworks Open Source Program Office (OSPO) on May 5, 2026. Changes: - README.md: rewritten with OSPO v2 template — license-specific migration guidance, Community & Support section, Contributing workflow, Security section pointing to security.owncloud.com + YesWeHack bug bounty - agents.md: AI agent context file with architecture, build commands, and OSPO Policy Constraints (GitHub Actions, Dependabot, Git Workflow) - CODE_OF_CONDUCT.md: redirect to https://owncloud.com/contribute/code-of-conduct/ - CONTRIBUTING.md: redirect to https://owncloud.com/contribute/ - SECURITY.md: redirect to https://security.owncloud.com + YesWeHack - SUPPORT.md: redirect to https://owncloud.com/contact-us/ + channels OSPO: https://kiteworks.com/opensource Signed-off-by: David Walter <david.walter@kiteworks.com>
1 parent 690c628 commit 556de65

6 files changed

Lines changed: 220 additions & 0 deletions

File tree

‎CODE_OF_CONDUCT.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
# Code of Conduct
2+
3+
This project follows the ownCloud Code of Conduct.
4+
5+
Please read the full Code of Conduct at:
6+
**<https://owncloud.com/contribute/code-of-conduct/>**
7+
8+
By participating in this project, you agree to abide by its terms.

‎CONTRIBUTING.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
# Contributing
2+
3+
Thank you for your interest in contributing to this project!
4+
5+
Please read the full contributing guidelines at:
6+
**<https://owncloud.com/contribute/>**
7+
8+
For development setup, coding standards, and pull request process,
9+
see the README in this repository.

‎README.md‎

Lines changed: 112 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,112 @@
1+
# davclient.js
2+
3+
<!-- OSPO-managed README | Generated: 2026-04-16 | v2 -->
4+
5+
[![License](https://img.shields.io/badge/License-BSD--3--Clause-blue.svg)](LICENSE) [![ownCloud OSPO](https://img.shields.io/badge/OSPO-ownCloud-blue)](https://kiteworks.com/opensource)
6+
7+
davclient.js is a JavaScript client library for WebDAV, CalDAV, and CardDAV protocols. It provides a lightweight API for performing DAV operations (PROPFIND, PROPPATCH, MKCOL, MOVE, COPY, DELETE, LOCK, UNLOCK, REPORT) from browser-based applications. The library is used by ownCloud's web frontend to communicate with the server's DAV endpoints.
8+
9+
> **Note:** This repository is in maintenance/legacy mode and is no longer actively developed.
10+
11+
## Part of Infrastructure / Tooling
12+
13+
This library is a shared JavaScript dependency used by ownCloud's web-based components to interact with DAV (WebDAV, CalDAV, CardDAV) servers. It supports the [ownCloud Server (Classic)](https://github.com/owncloud/core) web interface.
14+
15+
> **Note:** This repository is currently in Archived/Legacy mode. It is no longer actively maintained.
16+
17+
## Getting Started
18+
19+
Follow the steps below to install and use the library.
20+
21+
### Installation
22+
23+
Via npm:
24+
```bash
25+
npm install davclient.js
26+
```
27+
28+
Or via Bower:
29+
```bash
30+
bower install davclient.js
31+
```
32+
33+
### Running Tests
34+
35+
```bash
36+
npm test
37+
```
38+
39+
## Documentation
40+
41+
- See the source code in `lib/` for the API
42+
- The `index.html` file provides a usage example
43+
44+
## Community & Support
45+
46+
**[Star](https://github.com/owncloud/davclient.js)** this repo and **Watch** for release notifications!
47+
48+
- [ownCloud Website](https://owncloud.com)
49+
- [Community Discussions](https://github.com/orgs/owncloud/discussions)
50+
- [Matrix Chat](https://app.element.io/#/room/#owncloud:matrix.org)
51+
- [Documentation](https://doc.owncloud.com)
52+
- [Enterprise Support](https://owncloud.com/contact-us/)
53+
- [OSPO Home](https://kiteworks.com/opensource)
54+
55+
## Contributing
56+
57+
We welcome contributions! Please read the [Contributing Guidelines](CONTRIBUTING.md)
58+
and our [Code of Conduct](CODE_OF_CONDUCT.md) before getting started.
59+
60+
### Workflow
61+
62+
- **Rebase Early, Rebase Often!** We use a rebase workflow. Always rebase on the target branch before submitting a PR.
63+
- **Dependabot**: Automated dependency updates are managed via Dependabot. Review and merge dependency PRs promptly.
64+
- **Signed Commits**: All commits **must** be PGP/GPG signed. See [GitHub's signing guide](https://docs.github.com/en/authentication/managing-commit-signature-verification).
65+
- **DCO Sign-off**: Every commit must carry a `Signed-off-by` line:
66+
```
67+
git commit -s -S -m "your commit message"
68+
```
69+
- **GitHub Actions Policy**: Workflows may only use actions that are (a) owned by `owncloud`, (b) created by GitHub (`actions/*`), or (c) verified in the GitHub Marketplace.
70+
71+
## Security
72+
73+
**Do not open a public GitHub issue for security vulnerabilities.**
74+
75+
Report vulnerabilities at **<https://security.owncloud.com>** -- see [SECURITY.md](SECURITY.md).
76+
77+
Bug bounty: [YesWeHack ownCloud Program](https://yeswehack.com/programs/owncloud-bug-bounty-program)
78+
79+
## License
80+
81+
This project is licensed under the [BSD-3-Clause](LICENSE).
82+
83+
## About the ownCloud OSPO
84+
85+
The [Kiteworks Open Source Program Office](https://kiteworks.com/opensource), operating under
86+
the [ownCloud](https://owncloud.com) brand, launched on May 5, 2026, to steward the open source
87+
ecosystem around ownCloud's products. The OSPO ensures transparent governance, license compliance,
88+
community health, and sustainable collaboration between the open source community and
89+
[Kiteworks](https://www.kiteworks.com), which acquired ownCloud in 2023.
90+
91+
- **OSPO Home**: <https://kiteworks.com/opensource>
92+
- **GitHub**: <https://github.com/owncloud>
93+
- **ownCloud**: <https://owncloud.com>
94+
95+
For questions about the OSPO or licensing, contact ospo@kiteworks.com.
96+
97+
### License Migration to Apache 2.0
98+
99+
The OSPO is driving a strategic relicensing of ownCloud repositories toward the
100+
[Apache License 2.0](https://www.apache.org/licenses/LICENSE-2.0), following
101+
the [Apache Software Foundation's third-party license policy](https://www.apache.org/legal/resolved.html).
102+
103+
Individual repositories will migrate as their audit is completed. The LICENSE file
104+
in each repo reflects its **current** license status (not the target).
105+
106+
**Current license: BSD-3-Clause** (Category A per Apache policy -- permissive, compatible with Apache-2.0).
107+
108+
Migration prerequisites for this repository:
109+
110+
- **CLA/DCO coverage**: All past contributors must have signed agreements permitting relicensing
111+
- **Header updates**: All source file headers must be updated to Apache-2.0 notice
112+
- **Dependency audit**: Verify no incompatible transitive dependencies

‎SECURITY.md‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
# Security Policy
2+
3+
## Reporting a Vulnerability
4+
5+
**Do NOT open a public GitHub issue for security vulnerabilities.**
6+
7+
Please report security issues responsibly via:
8+
**<https://security.owncloud.com>**
9+
10+
You can also report vulnerabilities through our YesWeHack bug bounty program:
11+
**<https://yeswehack.com/programs/owncloud-bug-bounty-program>**

‎SUPPORT.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
# Support
2+
3+
For support with this project, please use the following channels:
4+
5+
- **Enterprise Support**: <https://owncloud.com/contact-us/>
6+
- **Community discussions**: https://github.com/orgs/owncloud/discussions
7+
- **Matrix Chat**: <https://app.element.io/#/room/#owncloud:matrix.org>
8+
- **Documentation**: <https://doc.owncloud.com>
9+
10+
Please do not use GitHub issues for general support questions.

‎agents.md‎

Lines changed: 70 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,70 @@
1+
# AI Agent Guidelines for davclient.js
2+
3+
This file provides context for AI coding agents (Claude Code, GitHub Copilot, Cursor, etc.) working in this repository.
4+
5+
## Repository Overview
6+
- **Product family:** Infrastructure / Tooling
7+
- **Primary language(s):** JavaScript
8+
- **Build system:** npm, Bower
9+
- **Test framework:** Karma
10+
- **CI system:** None detected
11+
12+
## Architecture & Key Paths
13+
- `lib/` - Library source code (JavaScript)
14+
- `tests/` - Karma test suite
15+
- `package.json` - npm package definition
16+
- `bower.json` - Bower package definition
17+
- `karma.conf.js` - Karma test runner configuration
18+
- `index.html` - Usage example
19+
- `package-lock.json` - npm lockfile
20+
21+
## Development Conventions
22+
- **Branching:** master
23+
- **Commit messages:** DCO sign-off required (`git commit -s`)
24+
- **Code style:** No specific linter configured
25+
- **PR process:** Open a PR against master. All CI checks must pass.
26+
- **Note:** This repository is in Archived/Legacy mode
27+
28+
## Build & Test Commands
29+
```bash
30+
# Install dependencies
31+
npm install
32+
33+
# Test
34+
npm test
35+
36+
# Lint
37+
Not detected
38+
```
39+
40+
## Important Constraints
41+
- All code contributions must be compatible with the **BSD-3-Clause** license
42+
- Do not introduce new **copyleft-licensed dependencies** (GPL, AGPL, LGPL, MPL) without explicit discussion in an issue first. This is especially important for repos migrating to Apache 2.0.
43+
- Do not introduce new dependencies without discussion in an issue first
44+
- This repository is in legacy/archived status
45+
46+
47+
## OSPO Policy Constraints
48+
49+
### GitHub Actions
50+
- **Only** use actions owned by `owncloud`, created by GitHub (`actions/*`), verified on the GitHub Marketplace, or verified by the ownCloud Maintainers.
51+
- Pin all actions to their full commit SHA (not tags): `uses: actions/checkout@<SHA> # vX.Y.Z`
52+
- Never introduce actions from unverified third parties.
53+
54+
### Dependency Management
55+
- Dependabot is configured for automated dependency updates.
56+
- Review and merge Dependabot PRs as part of regular maintenance.
57+
- Do not introduce new dependencies without discussion in an issue first.
58+
59+
### Git Workflow
60+
- **Rebase policy**: Always rebase; never create merge commits. Use `git pull --rebase` and `git rebase` before pushing.
61+
- **Signed commits**: All commits **must** be PGP/GPG signed (`git commit -S -s`).
62+
- **DCO sign-off**: Every commit needs a `Signed-off-by` line (`git commit -s`).
63+
- **Conventional Commits & Squash Merge**: Use the [Conventional Commits](https://www.conventionalcommits.org/) format where the repository enforces it. Many repos use squash merge, where the PR title becomes the commit message on the default branch — apply Conventional Commits format to PR titles as well. A reusable GitHub Actions workflow enforces this.
64+
65+
## Context for AI Agents
66+
- Match existing code style
67+
- Do not refactor unrelated code in the same PR
68+
- Write tests for new functionality
69+
- Keep PRs focused and atomic
70+
- Tests run in FirefoxHeadless via Karma

0 commit comments

Comments
 (0)