<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<!--[if IE]><meta http-equiv="X-UA-Compatible" content="IE=edge"><![endif]-->
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta name="generator" content="Asciidoctor 1.5.6.1">
<title>Eclipse Committer Due Diligence Guidelines</title>
<style>

</style>
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.6.3/css/font-awesome.min.css">
</head>
<body id="committers-dd" class="article toc2 toc-left">
<div id="header">
<h1>Eclipse Committer Due Diligence Guidelines</h1>
<div id="toc" class="toc2">
<div id="toctitle">Table of Contents</div>
<ul class="sectlevel1">
<li><a href="#introduction">Introduction</a></li>
<li><a href="#contributors">Contributors and Committers</a>
<ul class="sectlevel2">
<li><a href="#content-received">How Content is Received</a></li>
<li><a href="#content-distributed">How Content is Distributed</a></li>
</ul>
</li>
<li><a href="#procedures">Due Diligence Procedures</a>
<ul class="sectlevel2">
<li><a href="#contributions">Receiving contributions</a></li>
<li><a href="#appropriateness">Appropriateness of Contributions</a></li>
<li><a href="#cryptography">Cryptography</a></li>
<li><a href="#quality">Code Quality and Style</a></li>
<li><a href="#legaldoc">Legal Documentation</a></li>
<li><a href="#third-party">Third-Party Content</a></li>
<li><a href="#tracking">Tracking Contributions</a></li>
<li><a href="#summary">Summary</a></li>
</ul>
</li>
</ul>
</div>
</div>
<div id="content">
<div class="sect1">
<h2 id="introduction"><a class="anchor" href="#introduction"></a><a class="link" href="#introduction">Introduction</a></h2>
<div class="sectionbody">
<div class="paragraph">
<p>Eclipse Committers play a very important role in the operation of the Eclipse Foundation open source projects. This document outlines the responsibilities and explains some of the basic concepts Eclipse Committers need to understand in their role as a committer. If you are an Eclipse Committer, should you have any questions after reading this document, your questions should be submitted to your Project Management Committee (PMC) or the Eclipse Management Organization (EMO).</p>
</div>
</div>
</div>
<div class="sect1">
<h2 id="contributors"><a class="anchor" href="#contributors"></a><a class="link" href="#contributors">Contributors and Committers</a></h2>
<div class="sectionbody">
<div class="paragraph">
<p>Anyone who makes contributions to the Eclipse Foundation website and to Eclipse Foundation projects are considered to be Contributors. These Contributors submit contributions such as code, documentation, and other materials which must be received as <a href="https://www.eclipse.org/projects/handbook/#resources-commit">Git commits</a> using infrastructure provided by the Eclipse Foundation.Contributors that have made significant contributions to Eclipse Foundation projects may be promoted to Committer status. A Contributor may become a Committer once having been nominated and voted in by other Committers. The appointment of a new Committer is subject to confirmation by the relevant PMC. Committers have a responsibility to help ensure that all content redistributed on the Eclipse Foundation servers is appropriate. In the case of mailing list posts and issue reports, it is possible for Contributors to submit inappropriate content without the knowledge of Committers. If a Committer finds content on one of these systems that does not seem appropriate, based on the standards set out in this document or based on the Committer’s good judgement and experience, they should contact the EMO or a PMC member immediately.</p>
</div>
<div class="paragraph">
<p>Committers receive write-access to Eclipse Foundation <a href="https://www.eclipse.org/projects/handbook/#project-resources-and-services">resources and services</a> that contributors do not have. This includes write-access to the <a href="https://www.eclipse.org/projects/handbook/#resources-git">source code repositories</a>, the <a href="https://www.eclipse.org/projects/handbook/#resources-downloads">download servers</a>, and the <a href="https://www.eclipse.org/projects/handbook/#resources-website">web site</a>. Committed content in the source code repository becomes immediately available to Eclipse Foundation visitors and users. More importantly, this content is used to create daily builds that may be downloaded by thousands of people each day and may be incorporated into many free and commercially-available software products. Due to the potential for downstream redistribution, Committers are required to help ensure that inappropriate content is not placed in the source code repository. Content contributed to the webpages on the Eclipse Foundation website are less likely to be incorporated into software products. However, by their nature, they may be seen by visitors to the web site and their impact is generally more immediate.</p>
</div>
<div class="paragraph">
<p>Committers are usually contributors as well. In addition to incorporating and releasing content contributed by others, Committers may commit (often significant) contributions which they have developed themselves. Some Committers may never commit any content other than what they have authored themselves. Even though they may be more confident in the pedigree of their own contributions, they still need to ensure that their content is appropriate.</p>
</div>
<div class="sect2">
<h3 id="content-received"><a class="anchor" href="#content-received"></a><a class="link" href="#content-received">How Content is Received</a></h3>
<div class="paragraph">
<p>All content must be received as Git commits via infrastructure provided by the Eclipse Foundation. All content submitted through any channel other than the Eclipse Foundation infrastructure must be approved by the PMC, and submitted to the EMO, via a <a href="https://www.eclipse.org/projects/handbook/#ip-cq">Contribution Questionnaire</a> for due diligence approval, prior to being committed to the source code repository. It is highly recommended that each Committer review and understand <a href="https://www.eclipse.org/projects/handbook/#ip">Intellectual Property Management</a> at the Eclipse Foundation and the Eclipse Foundation’s <a href="https://www.eclipse.org/legal/EclipseLegalProcessPoster.pdf">Due Diligence Process</a> in particular.</p>
</div>
</div>
<div class="sect2">
<h3 id="content-distributed"><a class="anchor" href="#content-distributed"></a><a class="link" href="#content-distributed">How Content is Distributed</a></h3>
<div class="paragraph">
<p>Users and recipients of content distributed by the Eclipse Foundation are granted rights to the content by the declared project license(s). The project license(s) are described on the each project’s website, the <a href="https://www.eclipse.org/projects/handbook/#legaldoc-license">license</a> and <a href="https://www.eclipse.org/projects/handbook/#legaldoc-notice">notice</a> files in the project’s software repositories, and in the <a href="https://www.eclipse.org/projects/handbook/#ip-copyright-headers">copyright headers</a> of individual source files..</p>
</div>
</div>
</div>
</div>
<div class="sect1">
<h2 id="procedures"><a class="anchor" href="#procedures"></a><a class="link" href="#procedures">Due Diligence Procedures</a></h2>
<div class="sectionbody">
<div class="paragraph">
<p>Please see this Eclipse Legal process <a href="https://www.eclipse.org/legal/EclipseLegalProcessPoster.pdf">overview document</a> which provides a pictorial representation of the due diligence process.</p>
</div>
<div class="sect2">
<h3 id="contributions"><a class="anchor" href="#contributions"></a><a class="link" href="#contributions">Receiving contributions</a></h3>
<div class="paragraph">
<p>IMPORTANT NOTE: Committers should never accept a contribution received via a private communication such as email. It is important that all contributions are received through one of the channels described above to ensure that all necessary licenses are granted and that there is a public, timestamped, and archived record of the submission.</p>
</div>
<div class="paragraph">
<p>Before accepting every contribution, the Committer must check the following:</p>
</div>
<div class="olist arabic">
<ol class="arabic">
<li>
<p>That the name and email address of the Contributors are accurately captured;</p>
</li>
<li>
<p>That the Contributors have signed the  <a href="https://www.eclipse.org/legal/ECA.php">Eclipse Contributor Agreement</a> (ECA); and .</p>
</li>
<li>
<p>That the Contributor has signed-off the Contribution, indicating that they are in compliance with the <a href="https://www.eclipse.org/legal/DCO.php">Developer Certificate of Origin</a> as defined in the ECA.</p>
</li>
</ol>
</div>
<div class="paragraph">
<p>It is the responsibility of the Committer to verify that there is a valid ECA on file for the author(s) of each contribution.</p>
</div>
</div>
<div class="sect2">
<h3 id="appropriateness"><a class="anchor" href="#appropriateness"></a><a class="link" href="#appropriateness">Appropriateness of Contributions</a></h3>
<div class="paragraph">
<p>A Committer cannot always assume that contributed content can be freely used or redistributed. Committers are obligated to ensure the appropriate due diligence has been completed before incorporating and redistributing content received from others. The process for performing due diligence depends on whether the contribution is deemed to be a "significant" one. A "significant" contribution is a substantial amount of code or content that introduces major new functionality into the code base, or any code or module which will be distributed under any license other than the project license(s).</p>
</div>
<div class="paragraph">
<p>Any contribution greater than 1,000 lines of code is deemed to be "significant". If necessary, the EMO can assist in determining whether a contribution should be classified as "significant".</p>
</div>
<div class="paragraph">
<p>For "significant" contributions, the following three steps should be used in determining if the contributed content is suitable for committing to an Eclipse Foundation project,</p>
</div>
<div class="olist arabic">
<ol class="arabic">
<li>
<p>The Committer, possibly with assistance from the Contributors, must complete the Eclipse Foundation <a href="https://www.eclipse.org/projects/handbook/#ip-cq">Contribution Questionnaire</a> ("CQ").</p>
</li>
<li>
<p>The PMC must approve of the content’s suitability for the Eclipse Foundation project, and indicate their approval on the CQ. The analysis performed by the PMC is usually one of a purely technical nature.</p>
</li>
<li>
<p>The EMO must approve the contribution. This decision will be based upon the EMO’s due diligence review of the contribution’s content and licensing.</p>
</li>
</ol>
</div>
<div class="paragraph">
<p>For simple bug fixes and minor enhancements contributed under the <a href="https://www.eclipse.org/legal/epl/notice.php">Eclipse Foundation Terms of Use</a>, PMC and EMO approval is not required. However, the Committer is expected to ensure the appropriateness of the contribution and its availability for redistribution and modification by the Eclipse Foundation. There are many factors in making these determination, including things like license compatibility, confidentiality, copyright rights, patents, export control laws, no profanity, acceptable standards of code quality and coding style, etc. If a Committer has any concerns on these topics, they should seek assistance from the EMO.</p>
</div>
<div class="paragraph">
<p>If the contribution has any "legal" terms or conditions associated with it whatsoever (other than a simple statement saying the contribution is licensed under the project license(s)) the contribution must be approved by the appropriate PMC before being utilized. Possible "legal" terms or conditions include anything referring to "copyright", "patent", "trade secret", "confidential", "license" or "rights," or any other language purporting to grant or reserve any rights to use or distribute the contribution, or limit public distribution of the contribution. The PMC (with assistance from the EMO as necessary) will determine if the "legal" language is consistent with the project license(s) as applicable.</p>
</div>
<div class="paragraph">
<p>Given the amount of time required to complete the due diligence process on these packages, the Committer should allow sufficient time for the appropriate review process to complete.</p>
</div>
</div>
<div class="sect2">
<h3 id="cryptography"><a class="anchor" href="#cryptography"></a><a class="link" href="#cryptography">Cryptography</a></h3>
<div class="paragraph">
<p>If the contribution is known or is believed to contain any type of encryption or decryption software, the contribution must be approved by the appropriate PMC before being utilized.</p>
</div>
<div class="paragraph">
<p>Cryptographic content from the Eclipse Foundation has been given a classification as Export Commodity Control Number (ECCN) 5D002.C.1 by the U.S. Government Department of Commerce, Bureau of Export Administration, and is deemed eligible for export under 15 CFR §742.15(b), and deemed not subject to Export Administration Regulations as publicly available encryption source code classified ECCN 5D002.. However, under this license exception, the content may not contain cryptanalytic functionality, such as a cryptographic codebreaker. It is the Committer’s obligation to ensure that the content does not contain functionality that would require a change in export classification. If you have any questions regarding cryptography or export controls, please contact <a href="mailto:license@eclipse.org">license@eclipse.org</a>.</p>
</div>
<div class="paragraph">
<p>Any modifications, additions or removal of cryptographic code, should be brought to the PMC’s attention.</p>
</div>
<div class="paragraph">
<p>Any Contributions containing Cryptography should have information regarding the Cryptography documented in <a href="https://www.eclipse.org/projects/handbook/#legaldoc-notice">notices</a>  for the source code repository and distribution forms that contain the Contribution. The Committer should work with the EMO to ensure the notices file has the appropriate documentation before the contribution is committed to the source code repository.</p>
</div>
</div>
<div class="sect2">
<h3 id="quality"><a class="anchor" href="#quality"></a><a class="link" href="#quality">Code Quality and Style</a></h3>
<div class="paragraph">
<p>Each project may have its own standards for quality and style. However, any profanity found in the code or its comments are considered unacceptable and should be removed before the content is contributed. For more details on a specific project’s quality or style standards, please connect directly with the project team, or consult with the PMC.</p>
</div>
</div>
<div class="sect2">
<h3 id="legaldoc"><a class="anchor" href="#legaldoc"></a><a class="link" href="#legaldoc">Legal Documentation</a></h3>
<div class="paragraph">
<p>It is very important that all content contains the correct legal documentation. Please read the <a href="https://www.eclipse.org/projects/handbook/#legaldoc">Legal Documentation Requirements</a>.</p>
</div>
<div class="paragraph">
<p>If you require assistance in preparing any of this documentation, contact your PMC or the EMO. All legal documentation should be approved by the EMO prior to committing the content.</p>
</div>
</div>
<div class="sect2">
<h3 id="third-party"><a class="anchor" href="#third-party"></a><a class="link" href="#third-party">Third-Party Content</a></h3>
<div class="paragraph">
<p>There are cases where content redistributed at the Eclipse Foundation is not received as a contribution under the the project license(s). The most common case is a Committer who wishes to redistribute content maintained by another open source project, outside of the Eclipse Foundation. Some examples of such packages currently being redistributed by the Eclipse Foundation are projects maintained by <a href="http://www.apache.org/">The Apache Software Foundation</a>, <a href="http://www.mozilla.org/">Mozilla</a>, <a href="http://www.gtk.org/">GTK+</a>, <a href="http://www.junit.org/">JUnit</a>, <a href="http://www.jcraft.com/">JCraft</a>, and others.</p>
</div>
<div class="paragraph">
<p>Before any such package can be redistributed by the Eclipse Foundation, the Committer must create a <a href="https://www.eclipse.org/projects/handbook/#ip-cq">Contribution Questionnaire</a>, providing details of the package to the EMO and the PMC. The package will then be reviewed as follows:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>The PMC will decide whether the package’s functionality is required, and approve it for use by the project,</p>
</li>
<li>
<p>The EMO will decide on the compatibility of the contribution’s license with the project license(s), and</p>
</li>
<li>
<p>The EMO will initiate the <a href="https://www.eclipse.org/legal/EclipseLegalProcessPoster.pdf">IP due diligence review</a>.</p>
</li>
</ul>
</div>
</div>
<div class="sect2">
<h3 id="tracking"><a class="anchor" href="#tracking"></a><a class="link" href="#tracking">Tracking Contributions</a></h3>
<div class="paragraph">
<p>Tracking of each contribution within a project is very important from a legal point of view. As well, it allows for the appropriate acknowledgement of each contributor. This information about each contribution is typically maintained within <a href="https://www.eclipse.org/projects/handbook/#resources-commit">Git commit records</a>, and the standard <a href="https://www.eclipse.org/projects/handbook/#ip-copyright-headers">copyright headers</a> contained within individual source files.</p>
</div>
<div class="paragraph">
<p>Each project team must take steps to ensure that intellectual property is <a href="https://www.eclipse.org/projects/handbook/#resources-commit">properly received</a>, so that it can be tracked by the automated <a href="https://www.eclipse.org/projects/handbook/#ip-iplog">Intellectual Property Log</a> ("IP Log") infrastructure.</p>
</div>
</div>
<div class="sect2">
<h3 id="summary"><a class="anchor" href="#summary"></a><a class="link" href="#summary">Summary</a></h3>
<div class="paragraph">
<p>To help support downstream adoption of Eclipse Foundation projects, it is a necessity to exercise the appropriate due diligence. In addition to these specific standards, the community relies on Committers to exercise their own judgment with respect to other factors that may deem the contribution to be inappropriate for use. If a Committer has doubts about the appropriateness of the contribution for any reason, then that Committer should investigate and consult with the applicable PMC, who will call on or direct you to EMO resources if necessary.</p>
</div>
<hr>
<div class="paragraph">
<p>Last updated: December 19/2017</p>
</div>
</div>
</div>
</div>
</div>
</body>
</html>