Skip to content

Latest commit

 

History

History
27 lines (16 loc) · 3.34 KB

File metadata and controls

27 lines (16 loc) · 3.34 KB

Repository licensing and provenance

RexCode repositories use the licence and notices recorded in each repository. Their presence under the RexCode Digital GitHub organisation does not, by itself, establish copyright ownership.

  • Commercial products: source repositories may be private. Product-specific code is intended for commercial use; third-party and template material keeps the licence and notices that apply to it.
  • RexCode open source: each project states its own licence. Contributions remain the contributors’ copyright and are accepted under that project’s published contribution terms.
  • External forks and upstream contributions: retain upstream ownership, licence files, and notices. Do not treat a fork or contribution repository as a RexCode-owned product.
  • Third-party material: retain required attribution and licence notices, and document material copied or redistributed with a product.
  • Company ownership: founder, employee, or contractor work belongs to RexCode Digital Ltd only where supported by applicable written agreements. Repository placement and commit history are not substitutes for those agreements.

This page describes repository practice; it does not change the licence of any repository or third-party work.

Repository classification and lifecycle

Classify repositories by their purpose: commercial products, RexCode open-source products, organisation support, internal test/sandbox work, or external forks/upstream contributions. Repositories with unclear ownership or provenance stay unclassified until reviewed. Each repository's own licence and notices govern its contents.

Commercial repositories should document their product-specific proprietary posture without overriding upstream licences. Open-source repositories should publish their chosen licence and contribution terms. External forks and contribution repositories retain upstream ownership, licensing, and notices; do not relabel them as original RexCode products. Keep test/sandbox repositories clearly identified and free of production data.

Before archiving or deprecating a product, record its status, support boundary, successor (if any), and relevant release or data-retention steps in the repository. Preserve history, licences, and third-party notices. Repository deletion requires separate owner authorisation.

Security and contributions

Use private vulnerability reporting on the affected repository's Security tab where available. Otherwise report privately to hello@rexcode.co.uk; do not disclose vulnerabilities, secrets, or customer data publicly. Repository-specific SECURITY.md files define the applicable reporting instructions.

Each open-source project documents its own contribution terms, including the licence under which a contribution is accepted. Contributors retain copyright unless a separate written agreement says otherwise. Do not imply a CLA, DCO, or copyright assignment unless that process is actually adopted. Commercial repository access and work should be covered by the applicable employee or contractor agreement; repository access and commit history do not transfer title.

Each repository controls its own release/versioning process. Do not publish a package or release solely to refresh repository metadata; package contents and licence notices should be checked as part of the next authorised release.