Added policy pages (#20)

* added policy pages * updated links refering to policy pages * added 2 missing policy pages * clean up PR * format policy index page as npmjs.com * fixed policy urls to full path * updated the git history urls for policy pages * Update content/policies/index.mdx Co-authored-by: Myles Borins <mylesborins@github.com> * Removed receiving reports * Fix link * Fix link * Fix other link * Update Co-authored-by: t-dekell <59473246+t-dekell@users.noreply.github.com> Co-authored-by: Myles Borins <mylesborins@github.com> Co-authored-by: Deina Kellezi <t-dekell@github.com>

Demira committed Jul 16, 2021 at 10:56 UTC 89de7b8cf92946e80ab756d6a8a38f45b0ea3ac9
22 files changed +3230 -7
content/packages-and-modules/updating-and-managing-your-published-packages/transferring-a-package-from-a-user-account-to-another-user-account.mdx
+1 -1
@@ -45,5 +45,5 @@ npm owner add <their-username> <package-name> --otp=123456
45 npm owner rm <your-username> <package-name> --otp=123456
46 ```
47
48 -[dispute-policy]: https://www.npmjs.com/policies/disputes
48 +[dispute-policy]: /policies/disputes
49 [npm-owner]: cli/owner
content/packages-and-modules/updating-and-managing-your-published-packages/unpublishing-packages-from-the-registry.mdx
+3 -4
@@ -5,7 +5,7 @@ import shared from '../../../src/shared.js'
5
6 ## How to unpublish
7
8 -As a package owner or collaborator, if your package has no dependents, you can permanently remove it from the npm registry by using the CLI. You can [unpublish][unpublish-cli] within 72 hours of the initial publish. Beyond 72 hours,so you can still unpublish your package if [it meets certain criteria](https://www.npmjs.com/policies/unpublish).
8 +As a package owner or collaborator, if your package has no dependents, you can permanently remove it from the npm registry by using the CLI. You can [unpublish](https://docs.npmjs.com/cli/v7/commands/npm-unpublish) within 72 hours of the initial publish. Beyond 72 hours, you can still unpublish your package if [it meets certain criteria](https://www.npmjs.com/policies/unpublish).
9
10 <Note>
11
@@ -37,7 +37,7 @@ If you have [two-factor authentication][two-factor-auth] enabled for writes, you
37
38 **Note:** If you unpublish an entire package, you may not publish any new versions of that package until 24 hours have passed.
39
40 -</Note>
40 +</Note>
41
42 ## When to unpublish
43
@@ -61,9 +61,8 @@ You might want to unpublish a package because you:
61 If you are no longer interested in maintaining a package, but want it to remain available for users to install, or if your package has dependents, we'd recommend [deprecating][deprecate-cli] it. To learn about how to deprecate a package, see "[Deprecating and undeprecating packages or package versions][deprecate-package]".
62
63
64 -[unpublish-cli]: cli/unpublish
64 [oh-no]: https://blog.npmjs.org/post/101934969510/oh-no-i-accidentally-published-private-data-to
65 [deprecate-cli]: cli/deprecate
66 [deprecate-package]: deprecating-and-undeprecating-packages-or-package-versions
68 -[unpublish-policy]: https://www.npmjs.com/policies/unpublish
67 [two-factor-auth]: about-two-factor-authentication
68 +[unpublish]: /policies/unpublish
content/policies/business-solution-terms.mdx new
+523
@@ -0,0 +1,523 @@
1 +---
2 +title: npm Business Solution Terms
3 +---
4 +
5 +Version 4.2.1
6 +
7 +These terms and the **Quote** sent by _npm_ or presented to _Customer_ through npmjs.com or AWS Marketplace make up an agreement between **npm** and **Customer**.
8 +
9 +## Background
10 +
11 +- _npm_ develops computer software and services for installing, managing, and sharing **Packages** of computer code and data.
12 +
13 +- _npm_'s command-line interface, or **CLI**, allows programmers to create, download, and share _Packages_ through online repositories called registries. _npm_ licenses the _CLI_ on _Open-Source Terms_, so anyone can use it free of charge.
14 +
15 +- _npm_ hosts the world's largest and most-used registry of _Packages_, the **npm Public Registry**. All _Packages_ in the _npm Public Registry_ are public, and anyone can download them.
16 +
17 +- Most software developers search and discover _Packages_ in the _npm Public Registry_ through the **npm Website**, https://www.npmjs.com. Developers also visit the _npm Website_ to create and manage accounts for publishing _Packages_.
18 +
19 +- _npm_ uses its familiarity and expertise with the _CLI_, _npm Public Registry_, and _npm Website_ to develop and offer software services for sharing _Packages_ privately within organizations, and for performing security analysis of _Packages_ that organizations use.
20 +
21 +- **npm Orgs** gives organizations access to, and control over, a named space, or **Scope**, for public and private _Packages_ of their own, on the same infrastructure as the _npm Public Registry_.
22 +
23 +- **npm Enterprise** gives organizations access to their own, private registry, hosted on infrastructure separate from the _npm Public Registry_.
24 +
25 +- _npm_ publishes **Documentation** for the _CLI_, _npm Orgs_, and _npm Enterprise_ at https://docs.npmjs.com/.
26 +
27 +- This is an agreement for _npm_ to provide either _npm Orgs_ or _npm Enterprise_ for _Customer_, as **Customer's Solution**.
28 +
29 +- This agreement governs use of _Customer's Solution_. _Customer_'s use of the _npm Public Registry_, _npm Website_, and any other _npm_ services is governed by the terms of use for those offerings.
30 +
31 +## npm's Obligations
32 +
33 +### Host Customer's Solution
34 +
35 +_npm_ agrees to provide _Customer's Solution_ so that _Customer Personnel_ can use the _Feature Set_ via the Internet, with computers and software that meet the requirements set out in the _Documentation_.
36 +
37 +### Isolate npm Enterprise
38 +
39 +If _Customer's Solution_ is _npm Enterprise_, _npm_ agrees to run _npm Enterprise_ for _Customer_ in its own, isolated virtual environment, separated from environments used to run _npm Enterprise_ for other customers.
40 +
41 +### Provide a Scope
42 +
43 +If _Customer's Solution_ is _npm Orgs_, _npm_ agrees to provide _Customer_ its own, uniquely named _Scope_ for _Packages_ on _npm Public Registry_ infrastructure. If _Customer_ received the _Quote_ and selected a _Scope_ name through the _npm Website_, that will be the name of _Customer_'s _Scope_. Otherwise, _npm_ and _Customer_ will collaborate to identify an available _Scope_ name for _Customer_.
44 +
45 +### Maintain Customer's Solution
46 +
47 +_npm_ agrees to update _Customer's Solution_ with software updates and fixes made generally available to other customers paying for the same solution. Updates and fixes do not include new or preexisting add-on features and complimentary services for which _npm_ charges additional fees.
48 +
49 +### Allow High-Volume Use of the npm Public Registry
50 +
51 +While this agreement continues and _Customer_ has paid all fees as required by this agreement, _npm_ waives the rule of its terms of service for the _npm Public Registry_ that prohibits _Customer_ from making an unreasonable volume of requests. _Customer_ may make up to 500,000,000 requests to the _npm Public Registry_ in any rolling thirty-calendar-day period, through _Customer's Solution_ or otherwise. This agreement does not change the terms of service for the _npm Public Registry_ in any other way.
52 +
53 +### Publish Documentation
54 +
55 +_npm_ agrees to publish the _Documentation_ so _Customer_ personnel can read it on the World Wide Web.
56 +
57 +### Maintain the CLI
58 +
59 +_npm_ agrees to publish a version of the _CLI_ compatible with _Customer's Solution_, free of charge, on _Open-Source Terms_.
60 +
61 +### List Customer as a Supporter
62 +
63 +If the _Quote_ specifies a promotional tier, then _npm_ agrees to display _Customer_'s logotype with those of other sponsors of the same tier on the _npm Website_.
64 +
65 +### Keep Customer Data Confidential
66 +
67 +_npm_ agrees not to access, use, or disclose _Customer Data_ without _Permission_, except:
68 +
69 +- as needed to host _Customer's Solution_
70 +
71 +- to monitor use of _Customer's Solution_ to prevent, detect, and mitigate breach of this agreement
72 +
73 +- to improve _Customer's Solution_ and the efficiency with which _npm_ provides it, to _Customer_ and others
74 +
75 +- to respond to _Technical Support Requests_
76 +
77 +### Take Security Precautions
78 +
79 +_npm_ agrees to take industry-standard security precautions to defend _Customer's Solution_ from malicious technical attack and _Data Breach_. _npm_ does not guarantee that _Customer's Solution_ will be completely free of software bugs or configuration errors affecting security, or completely secure from all possible technical attack.
80 +
81 +### Provide Technical Support
82 +
83 +#### Technical Support
84 +
85 +_npm_ agrees to task _npm_ **Support Personnel** with responding to **Technical Support Requests** from _Customer Personnel_. _Technical Support Requests_ must be opened at https://npmjs.com/support/.
86 +
87 +#### Scope of Technical Support
88 +
89 +_npm_ agrees to task _Support Personnel_ with diagnosing and resolving _Technical Support Requests_ related to configuring standard features of _Customer's Solution_ per the _Documentation_, use of the _CLI_ with _Customer's Solution_, downtime or software errors encountered when using _Customer's Solution_, and threats of malicious technical attack or _Data Breach_.
90 +
91 +#### Support Request Triage
92 +
93 +- **Critical Support Requests** are _Technical Support Requests_ that report that:
94 +
95 + - Systems providing _Customer's Solution_ are down or unresponsive.
96 +
97 + - _Users_ cannot download from or publish to _Customer's Solution_.
98 +
99 + - _Customer's Solution_ is under imminent threat of malicious technical attack or _Data Breach_.
100 +
101 +- All other _Technical Support Requests_ are **Regular Support Requests**.
102 +
103 +#### Technical Support Responsiveness
104 +
105 +##### Support Offerings
106 +
107 +- If _Customer's Solution_ is _npm Enterprise_, then _npm_ agrees to provide _Premium Support_. _npm_ does not offer _npm Enterprise_ with _Basic Support_.
108 +
109 +- If _Customer's Solution_ is _npm Orgs_, then _npm_'s support commitment depends on the _Quote_. If the _Quote_ specifies _Premium Support_, then _npm_ agrees to provide _Premium Support_. Otherwise, by default, _npm_ agrees to provide _Basic Support_.
110 +
111 +##### Premium Support
112 +
113 +**Premium Support** means that _npm_ will:
114 +
115 +- Respond to _Critical Support Requests_ within three _Business Hours_, and update on status every two Business Hours.
116 +
117 +- Respond to _Regular Support Requests_ within eight _Business Hours_.
118 +
119 +##### Basic Support
120 +
121 +**Basic Support** means that _npm_ will:
122 +
123 +- Respond to _Critical Support Requests_ within eight _Business Hours_, and update on status every Business Day.
124 +
125 +- Respond to _Regular Support Requests_ within sixteen _Business Hours_.
126 +
127 +#### Technical Support Escalation
128 +
129 +_npm_ agrees to task _Support Personnel_ with promptly escalating _Technical Support Requests_ that _Support Personnel_ cannot resolve independently to _npm_ engineering personnel responsible for _Customer's Solution_. In general, _Support Personnel_ will remain the primary point of contact for _Customer Personnel_, coordinate with _npm_ engineering personnel, and relay questions, advice, and progress to _Customer Personnel_. Where appropriate, _Support Personnel_ may connect _Customer Personnel_ to _npm_ engineering personnel directly.
130 +
131 +#### Refund Fees for Unresponsive Technical Support
132 +
133 +If _npm_ fails to meet [Technical Support Responsiveness](#technical-support-responsiveness) for three _Billing Periods_ in a row, and _Customer_ ends this agreement at the end of those _Billing Periods_, citing poor support responsiveness, _npm_ agrees to refund any _Prepaid Fees_, as well as 5% of all fees that _Customer_ paid for the three _Billing Periods_.
134 +
135 +### Honor any Uptime Commitment
136 +
137 +If _npm_ makes an **Uptime Commitment** in the _Quote_:
138 +
139 +#### Service-Level Agreement
140 +
141 +So long as _Customer's Solution_ remains within the _Use Limits_ and customer abides by [Follow Rules About Use](#follow-rules-about-use) and [Enforce Rules About Use](#enforce-rules-about-use), _npm_ agrees to host _Customer's Solution_ with _Uptime_ no less than the _Uptime Commitment_.
142 +
143 +#### Give Credits for Low Uptime
144 +
145 +_npm_ agrees to credit _Customer_'s account on _Notice_ and verification that _npm_ failed to provide service according to [Service-Level Agreement](#service-level-agreement) in the current _Billing Period_ or any of the three prior _Billing Periods_:
146 +
147 +- 5% of _Service Fees_ for any _Billing Period_ with _Uptime_ between zero and one percentage point less than the _Uptime Commitment_
148 +
149 +- 10% of _Service Fees_ for any _Billing Period_ with _Uptime_ between one and two percentage points less than the _Uptime Commitment_
150 +
151 +- 25% of _Service Fees_ for any _Billing Period_ with _Uptime_ at or below three percentage points less than the _Uptime Commitment_
152 +
153 +#### Apply Credits for Low Uptime
154 +
155 +_npm_ agrees to apply any credits under [Give Credits for Low Uptime](#give-credits-for-low-uptime) against _Customer_'s obligations to pay fees as soon as possible. _npm_ does not agree to refund any credits.
156 +
157 +#### Refund Fees for Low Uptime
158 +
159 +If _npm_ credits _Customer_'s account under [Give Credits for Low Uptime](#give-credits-for-low-uptime) for three _Billing Periods_ in a row, and _Customer_ ends this agreement at the end of those _Billing Periods_, citing low _Uptime_, _npm_ agrees to refund all _Service Fees_ that _Customer_ paid for the three _Billing Periods_, as well as any _Prepaid Fees_.
160 +
161 +### Use Responsible Subcontractors
162 +
163 +_npm_ agrees to take responsibility for any breach of [Keep Customer Data Confidential](#keep-customer-data-confidential), [Take Security Precautions](#take-security-precautions), [Prepare for Disasters](#prepare-for-disasters), or [Keep Malicious Code Out of the Software](#keep-malicious-code-out-of-the-software) by _npm_ employees and contractors, as if _npm_ breached itself.
164 +
165 +### Refund Prepaid Fees for Removed Features
166 +
167 +If _npm_ changes or removes features from _Customer's Solution_, substantially reducing how useful _Customer's Solution_ is to _Customer_, and _Customer_ ends this agreement in the same _Billing Period_ as the change or the next _Billing Period_, citing the change, _npm_ agrees to refund any _Prepaid Fees_.
168 +
169 +### Keep Malicious Code Out of the Software
170 +
171 +_npm_ agrees to take industry-standard precautions to keep the software that _npm_ runs to provide _Customer's Solution_ free of computer viruses, Trojans, worms, and other malicious code.
172 +
173 +### Prepare for Disasters
174 +
175 +_npm_ agrees to:
176 +
177 +- adopt, maintain, and periodically review a written plan to recover from any _Disaster_ affecting the systems used to provide _Customer's Solution_ or the integrity of _Customer Data_
178 +
179 +- share the plan with relevant _npm_ personnel
180 +
181 +- follow the plan if a _Disaster_ happens
182 +
183 +### Protect Customer from Liability
184 +
185 +So long as _Customer_ has paid all fees as required by this agreement:
186 +
187 +#### Indemnify Customer
188 +
189 +Subject to [How to Receive Indemnification](#how-to-receive-indemnification), _npm_ agrees to give _Customer_ _Indemnification_ for _Legal Claims_ by others alleging that _Permitted Use of Customer's Solution_ infringes any copyright, trademark, or trade secret right, or breaks any law.
190 +
191 +#### Provide Assurance About Patents
192 +
193 +As of the day _npm_ signs this agreement, _npm_ employees are not aware of any patent that _npm_ would infringe by selling _Customer's Solution_ under this agreement, or that _Customer_ would infringe by _Permitted Use of Customer's Solution_.
194 +
195 +#### Give Notice of Infringement or Noncompliance Claims
196 +
197 +_npm_ agrees to give _Customer_ prompt _Notice_ of any _Infringement or Noncompliance Claim_.
198 +
199 +### Protect Customer After this Agreement Ends
200 +
201 +[Keep Customer Data Confidential](#keep-customer-data-confidential) and [Indemnify Customer](#indemnify-customer) will continue after this agreement ends.
202 +
203 +## Customer's Obligations
204 +
205 +### Pay Fees
206 +
207 +_Customer_ agrees to pay all **Service Fees** for _Customer's Solution_ in advance, for each _Billing Period_, according to the _Quote_. _Customer_ agrees to pay all tax on fees, except tax _npm_ owes on income.
208 +
209 +### Handle Tax Withholding
210 +
211 +If _Customer_ is located outside the United States, and local law requires _Customer_ to withhold taxes on fees paid under this agreement:
212 +
213 +- _Customer_ agrees to make the required tax withholding payments for _npm_ by deducting the right amounts from payments to _npm_ and paying them to the proper tax authorities.
214 +
215 +- _Customer_ agrees to increase the amount of each payment made under this agreement to offset withholding, so that _npm_ receives the full amount owed according to the _Quote_.
216 +
217 +- _Customer_ agrees to provide _npm_ relevant official tax documentation and tax receipts showing that withholding was required, and that proper withholding payment has been made, as soon as possible after making any withholding payment.
218 +
219 +### Follow Rules About Use
220 +
221 +_Customer_ agrees not to:
222 +
223 +- infringe anyone else's _Intellectual Property Right_ using _Customer's Solution_
224 +
225 +- violate anyone else's rights using _Customer's Solution_
226 +
227 +- breach any agreement using _Customer's Solution_
228 +
229 +- break the law using _Customer's Solution_
230 +
231 +- reverse engineer _Customer's Solution_
232 +
233 +- circumvent any access controls or other limits of _Customer's Solution_
234 +
235 +- circumvent code in _Customer's Solution_ that monitors, reports on, or enforces _Use Limits_
236 +
237 +- strain the technical infrastructure of _Customer's Solution_ with an unreasonable volume of requests, or requests designed to impose an unreasonable load on IT systems underlying _Customer's Solution_
238 +
239 +- license, sell, lease, or otherwise let anyone but _Customer Personnel_ use _Customer's Solution_
240 +
241 +- furnish _Customer Data_ in any way that infringes any _Intellectual Property Right_, breaks any law, or breaches any other agreement
242 +
243 +- furnish _Customer Data_ subject to _Special Data Regulations_
244 +
245 +- reuse any one set of _Access Credentials_ for multiple _Users_
246 +
247 +- remove proprietary notices from _Customer's Solution_ or the _Documentation_
248 +
249 +- use _Customer's Solution_ to assess whether or how to create a competitive offering, or to assess the competitive strengths or weaknesses of _Customer's Solution_ in comparison to a current or potential _Customer_ offering
250 +
251 +- publish data about the performance of _Customer's Solution_
252 +
253 +### Keep Access Credentials Secret and Secure
254 +
255 +_Customer_ agrees to keep _Access Credentials_ secret and secure, and to share and distribute _Access Credentials_ only as needed to use _Customer's Solution_ and services under this agreement.
256 +
257 +### Enforce Rules About Use
258 +
259 +_Customer_ agrees to take responsibility for any breach of [Follow Rules About Use](#follow-rules-about-use) or [Keep Access Credentials Secret and Secure](#keep-access-credentials-secret-and-secure) by _Customer Personnel_, as if _Customer_ breached itself.
260 +
261 +### Update Account Details
262 +
263 +_Customer_ agrees to use the _Account Dashboard_ to keep its contact, payment, and other administrative details complete, accurate, and up-to-date.
264 +
265 +### Indemnify npm
266 +
267 +Subject to [How to Receive Indemnification](#how-to-receive-indemnification), _Customer_ agrees to give _npm_ _Indemnification_ from _Legal Claims_ by others based on:
268 +
269 +- breach of this agreement
270 +
271 +- _Customer Data_
272 +
273 +- _Use of Customer's Solution at Customer's Own Risk_
274 +
275 +- misuse of _Customer_'s _Access Credentials_
276 +
277 +### Protect npm After this Agreement Ends
278 +
279 +[Pay Fees](#pay-fees) and [Indemnify npm](#indemnify-npm) will continue after this agreement ends.
280 +
281 +## Intellectual Property
282 +
283 +### Existing and Outside IP
284 +
285 +This agreement does not change ownership of any _Intellectual Property Right_ held by either side, before or after entering this agreement.
286 +
287 +### Copyright License
288 +
289 +_npm_ grants _Customer_ and each of the _Users_ a _Standard License_, for any copyrights _npm_ can license, as needed to make _Permitted Use of Customer's Solution_ and read the _Documentation_.
290 +
291 +### Patent License
292 +
293 +_npm_ grants _Customer_ and each of the _Users_ a _Standard License_, for any patents _npm_ can license, as needed to make _Permitted Use of Customer's Solution_.
294 +
295 +### No Other Licenses
296 +
297 +Except for the licenses in [Intellectual Property](#intellectual-property), this agreement does not license or assign any _Intellectual Property Right_.
298 +
299 +### Public Licenses
300 +
301 +The terms of this agreement are separate from, and independent of, the terms of any public licenses that _npm_ grants for the _CLI_ or other _npm_ software.
302 +
303 +## Changes
304 +
305 +### Changes Customer May Make
306 +
307 +Subject to [How to Make Changes](#how-to-make-changes):
308 +
309 +- _Customer_ may end this agreement at any time.
310 +
311 +- If the _Quote_ specifies a way to calculate fees for different _Use Limits_, _Customer_ may change its _Use Limits_ within the limits specified in the _Quote_ at any time. _Customer_ changes to _Use Limits_ take effect as soon as _Customer_ pays any added fees.
312 +
313 +- _Customer_ may grant and revoke access to _Customer's Solution_ to _Users_' _npm_ accounts within _Customer_'s _Use Limits_.
314 +
315 +### Changes npm May Make
316 +
317 +Subject to [How to Make Changes](#how-to-make-changes):
318 +
319 +- _npm_ may end this agreement on the next date it would otherwise renew by giving _Notice_ at least one month in advance.
320 +
321 +- _npm_ may end this agreement immediately if _Customer_ breaches this agreement and fails to cure the breach within seven calendar days of _Notice_.
322 +
323 +- _npm_ may add, remove, and change software features of _Customer's Solution_.
324 +
325 +- _npm_ may change the _Documentation_.
326 +
327 +- _npm_ may take any of these steps in response to an _Infringement or Noncompliance Claim_:
328 +
329 + - _npm_ may upgrade _Customer's Solution_ so that _Permitted Use of Customer's Solution_ will no longer infringe or break the law.
330 +
331 + - _npm_ may change how it provides _Customer's Solution_ so that use of _Customer's Solution_ will no longer infringe or break the law.
332 +
333 + - If the problem is infringement, _npm_ may get a license for _Customer_ so that use of _Customer's Solution_ will no longer infringe.
334 +
335 + - If the problem is illegality, _npm_ may get the government approvals, licenses, or other requirements needed to abide by the law.
336 +
337 + - _npm_ may end this agreement and refund any _Prepaid Fees_.
338 +
339 +### Renewal
340 +
341 +This agreement begins on the date in the _Quote_ and continues for the initial term in the _Quote_. If the _Quote_ does not specify an initial term, this agreement continues for an initial term of one _Billing Period_. Unless the _Quote_ says otherwise, this agreement renews automatically for consecutive _Billing Periods_ after the initial term.
342 +
343 +## Liability
344 +
345 +### Agreed Legal Remedies
346 +
347 +- _Customer_'s only legal remedy for failures to meet [Technical Support Responsiveness](#technical-support-responsiveness) will be credits under [Refund Fees for Unresponsive Technical Support](#refund-fees-for-unresponsive-technical-support).
348 +
349 +- _Customer_'s only legal remedies for failures to meet [Honor any Uptime Commitment](#honor-any-uptime-commitment) will be credits under [Apply Credits for Low Uptime](#apply-credits-for-low-uptime) and refunds under [Refund Fees for Low Uptime](#refund-fees-for-low-uptime).
350 +
351 +- _Customer_'s only legal remedy for changes to the software features of _Customer's Solution_ will be refunds under [Refund Prepaid Fees for Removed Features](#refund-prepaid-fees-for-removed-features).
352 +
353 +- Each side's only legal remedy for _Legal Claims_ covered by _Indemnification_ will be _Indemnification_.
354 +
355 +### Valid Excuses
356 +
357 +Neither side will be liable for any failure or delay in meeting any obligation under this agreement caused by a _Disaster_, failure of the other side or its personnel to meet their obligations under this agreement, or actions done or delayed on specific written request of the other side.
358 +
359 +### Only Express Warranties
360 +
361 +***Except for its obligations in [npm's Obligations](#npms-obligations), _npm_ provides _Customer's Solution_ "as is", without any warranty at all. _npm_ disclaims any warranties the law might otherwise imply, like warranties of merchantability, fitness for any particular purpose, title, or noninfringement.***
362 +
363 +### Limited Damages
364 +
365 +#### Damages Limit
366 +
367 +***Subject to [Damages Limit Exceptions](#damages-limit-exceptions), neither side's total liability under this agreement will exceed the amount of fees _npm_ received from _Customer_ during the twelve months before the first claim is filed. This limit applies even if the side liable is advised that the other side may suffer damages.***
368 +
369 +#### Damages Exclusion
370 +
371 +***Neither side will be liable for breach-of-contract damages they could not have reasonably foreseen when entering this agreement.***
372 +
373 +#### Damages Limit Exceptions
374 +
375 +[Limited Damages](#limited-damages) does not limit damages for breach of:
376 +
377 +- [Keep Customer Data Confidential](#keep-customer-data-confidential)
378 +
379 +- [Provide Assurance About Patents](#provide-assurance-about-patents)
380 +
381 +- [Indemnify Customer](#indemnify-customer)
382 +
383 +- [Pay Fees](#pay-fees)
384 +
385 +- [Follow Rules About Use](#follow-rules-about-use)
386 +
387 +- [Enforce Rules About Use](#enforce-rules-about-use)
388 +
389 +- [Indemnify npm](#indemnify-npm)
390 +
391 +## Process
392 +
393 +### How to Receive Indemnification
394 +
395 +Both sides agree that to receive _Indemnification_ under this agreement, they must give _Notice_ of any covered _Legal Claims_ quickly, allow the other side to control investigation, defense, and settlement, and cooperate with those efforts. Both sides agree that if they fail to give _Notice_ of any covered _Legal Claims_ quickly, _Indemnification_ will not cover amounts that could have been defended against or mitigated if _Notice_ had been given quickly. Both sides agree that if they take control of the defense and settlement of any _Legal Claims_ covered by _Indemnification_, they will not agree to any settlements that admit fault for, or impose obligations on, the other side without their _Permission_.
396 +
397 +### How to Give Notice
398 +
399 +Both sides agree that to give _Notice_ under this agreement, the side giving _Notice_ must send by e-mail to the address the recipient provided on entering into this agreement, to _npm_ at legal@npmjs.com, or to a different address given later for _Notice_ going forward. If either side finds that e-mail can't be delivered to the address given, it may give _Notice_ by registered mail to the address on file for the recipient with the state under whose laws it is organized.
400 +
401 +### How to Make Changes
402 +
403 +_Customer_ agrees to make changes to this agreement through the account dashboard of _Customer's Solution_ whenever possible. If the account dashboard does not provide a user interface for making a particular change, or the account dashboard is not available or malfunctions, _Customer_ may make its change by _Notice_ to _npm_. _npm_ agrees to make changes to this agreement by _Notice_.
404 +
405 +## General Contract Terms
406 +
407 +### Governing Law
408 +
409 +California law will govern this agreement.
410 +
411 +### Government Procurement
412 +
413 +_npm Orgs_ and _npm Enterprise_ are commercial computer software, and the _Documentation_ is commercial computer software documentation. All were developed exclusively at private expense. If _Customer_'s procurement is subject to Federal Acquisition Regulation 12.212 or Defense Federal Acquisition Regulation Supplement 227.7202, _Customer_'s rights will be only those stated in this agreement.
414 +
415 +### Publicity
416 +
417 +_npm_ may identify _Customer_ as an _npm_ customer to current and potential customers, and may list _Customer_'s business name and logotype in promotional materials, such as _npm_'s websites.
418 +
419 +### Whole Agreement
420 +
421 +Both parties intend these terms, together with the _Quote_, as the final, complete, and only expression of their terms about use of _Customer's Solution_. However, this agreement does not affect the terms of any separate nondisclosure or confidentiality agreement _npm_ and _Customer_ may have.
422 +
423 +### Enforcement
424 +
425 +Only _npm_ and _Customer_ may enforce this agreement.
426 +
427 +### Assignment
428 +
429 +Each party may assign all its rights, licenses, and obligations under this agreement, as a whole, to a new legal entity created to change its jurisdiction or legal form of organization, or to an entity that acquires substantially all of its assets or enough securities to control its management. Otherwise, each party needs _Permission_ to assign any right, license, or obligation under this agreement. Attempts to assign against this agreement will have no legal effect.
430 +
431 +### Lawsuits
432 +
433 +#### Forum
434 +
435 +Both sides agree to bring any _Lawsuit_ in the state and federal courts sitting in the cities of San Francisco and Oakland, California \(the **Designated Courts**\).
436 +
437 +#### Exclusive Jurisdiction
438 +
439 +Both sides consent to the exclusive jurisdiction of the _Designated Courts_. Both sides may enforce judgments from the _Designated Courts_ in other jurisdictions.
440 +
441 +#### Inconvenient Forum Waiver
442 +
443 +Both sides waive any objection to venue for any _Lawsuit_ in the _Designated Courts_ and any claim that the other brought any _Lawsuit_ in the _Designated Courts_ in an inconvenient forum.
444 +
445 +## Definitions
446 +
447 +- **Access Credentials** means a user name and password, license key, or other secret that affords use of _Customer's Solution_.
448 +
449 +- **Account Dashboard** means the account management section of the _npm Website_.
450 +
451 +- **Billing Period** means a successive, month-long period. The first _Billing Period_ starts on the date of this agreement. The plural is **Billing Periods**.
452 +
453 +- **Business Day** means a day other than a Saturday, Sunday, or a day when commercial banks in San Francisco, California typically stay closed. The plural is **Business Days**.
454 +
455 +- **Business Hour** means an hour between 0900 and 1800 Pacific Time on a _Business Day_. The plural is **Business Hours**.
456 +
457 +- **Customer Data** means data that:
458 +
459 + - _Users_ furnish to _Customer's Solution_, such as by entering it or configuring _Customer's Solution_ to gather or receive it, if doing so doesn't breach this agreement
460 +
461 + - _Customer's Solution_ collects about _Users_ and how they use _Customer's Solution_
462 +
463 + - _Customer Personnel_ furnish to _Support Personnel_ via _Technical Support Requests_
464 +
465 +- **Customer Personnel** means _Customer_'s employees and each _Customer_ subsidiary's employees, as well as individuals providing services to _Customer_ as independent contractors.
466 +
467 +- **Data Breach** means malicious technical compromise, unauthorized access to, or unauthorized disclosure of _Customer Data_.
468 +
469 +- **Disaster** means:
470 +
471 + - fire, flood, earthquake, and other natural disasters
472 +
473 + - declared and undeclared war, act of terrorism, sabotage, riot, civil disorder, rebellion, and revolution
474 +
475 + - extraordinary malfunction of Internet infrastructure, data centers, or communications utilities
476 +
477 + - malicious technical attack on systems providing _Customer's Solution_
478 +
479 + - government action taken in response to any of these
480 +
481 +- **Feature Set** means all software features of _Customer's Solution_ described in the _Documentation_ on the date of this agreement.
482 +
483 +- **Indemnification** means indemnity and holding harmless for all liability, expenses, damages, and costs.
484 +
485 +- **Infringement or Noncompliance Claim** means a court order against use of _Customer's Solution_ based on a claim that it infringes any _Intellectual Property Right_, or breaks any law, or a threat of that kind of claim that _npm_ believes credible.
486 +
487 +- **Intellectual Property Right** means any patent, copyright, trademark, or trade secret right, or any other legal right typically referred to as an intellectual property right.
488 +
489 +- **Lawsuit** means a lawsuit brought by one side against the other, related to this agreement or _Customer's Solution_.
490 +
491 +- **Legal Claims** means claims, demands, lawsuits, and other legal actions.
492 +
493 +- **Notice** means a written communication from one side to the other per [How to Give Notice](#how-to-give-notice).
494 +
495 +- **Open-Source Terms** means the terms of a form license approved by the Open Source Initiative.
496 +
497 +- **Permission** means prior _Notice_ of consent.
498 +
499 +- **Permitted Use of Customer's Solution** means _Customer_'s use of _Customer's Solution_, other than _Use of Customer's Solution at Customer's Own Risk_.
500 +
501 +- **Prepaid Fees** means fees _Customer_ prepaid for _Billing Periods_ yet to begin.
502 +
503 +- **Special Data Regulations** means laws and regulations that impose special requirements on the collection, storage, processing, or transmission of particular kinds of data about individuals. The Gramm-Leach-Bliley Act, Health Insurance Portability and Accountability Act, Children's Online Privacy Protection Act, and Fair Credit Reporting Act are some _Special Data Regulations_. Laws that apply to data merely because they may identify specific individuals are not _Special Data Regulations_.
504 +
505 +- **Standard License** means a nonexclusive license during the term of this agreement, without rights to sublicense, that is conditional on payment of all fees as required by this agreement and limited by the _Use Limits_.
506 +
507 +- **Use of Customer's Solution at Customer's Own Risk** means:
508 +
509 + - use of _Customer's Solution_ in breach of this agreement
510 +
511 + - use of _Customer's Solution_ with changes, additions, or in combination with other software, systems, or data, in a way that infringes someone else's _Intellectual Property Right_ or breaks the law, if use of _Customer's Solution_ as provided, as described by the _Documentation_, would not
512 +
513 + - unauthorized use of _Customer's Solution_ with _Customer_ _Access Credentials_
514 +
515 +- **Uptime** means the percentage of wall-clock time during a _Billing Period_ when _Users_ can download from, publish to, and search _Customer's Solution_, subject to [Valid Excuses](#valid-excuses).
516 +
517 +- **Use Limits** means any numeric limits on use of _Customer's Solution_ specified in the _Quote_, such as a limit on number of _Users_.
518 +
519 +- **Users** means _Customer Personnel_ that _Customer_ configures _Customer's Solution_ to allow to:
520 +
521 + - download or publish _Packages_ to _Customer_'s _Scope_, if _Customer's Solution_ is _npm Orgs_
522 +
523 + - download or publish _Packages_ to _Customer_'s instance of _npm Enterprise_, if _Customer's Solution_ is _npm Enterprise_
content/policies/conduct.mdx new
+186
@@ -0,0 +1,186 @@
1 +---
2 +title: npm Code of Conduct
3 +---
4 +npm exists to facilitate sharing code, by making it easy for
5 +JavaScript module developers to publish and distribute packages.
6 +
7 +npm is a piece of technology, but more importantly, it is a community.
8 +
9 +We believe that our mission is best served in an environment that is
10 +friendly, safe, and accepting; free from intimidation or harassment.
11 +
12 +Towards this end, certain behaviors and practices will not be
13 +tolerated.
14 +
15 +## tl;dr
16 +
17 +* Be respectful.
18 +* We're here to help
19 +* Abusive behavior is never tolerated.
20 +* Data published to npm is hosted at the discretion of the service
21 + administrators, and may be removed.
22 +* Violations of this code may result in swift and permanent expulsion
23 + from the npm community.
24 +
25 +## Scope
26 +
27 +We expect all members of the npm community, including paid and unpaid
28 +agents, administrators, users, and customers of npm, Inc., to abide by
29 +this Code of Conduct at all times in all npm community venues, online
30 +and in person, and in one-on-one communications pertaining to npm
31 +affairs.
32 +
33 +This policy covers the usage of the npm registry, as well as the npm
34 +website, npm related events, and any other services offered by or on
35 +behalf of npm, Inc. (collectively, the "Service"). It also applies to
36 +behavior in the context of the npm Open Source project communities,
37 +including but not limited to public GitHub repositories, IRC channels,
38 +social media, mailing lists, and public events.
39 +
40 +This Code of Conduct is in addition to, and does not in any way
41 +nullify or invalidate, any other terms or conditions related to use of
42 +the Service.
43 +
44 +The definitions of various subjective terms such as "discriminatory",
45 +"hateful", or "confusing" will be decided at the sole discretion of
46 +the npm abuse team.
47 +
48 +## Friendly Harassment-Free Space
49 +
50 +We are committed to providing a friendly, safe and welcoming
51 +environment for all, regardless of gender identity, sexual
52 +orientation, ability, ethnicity, religion, age, physical
53 +appearance, body size, race, or similar personal characteristics.
54 +
55 +We ask that you please respect that people have differences of opinion
56 +regarding technical choices, and that every design or implementation
57 +choice carries a trade-off and numerous costs. There is seldom a
58 +single right answer. A difference of technology preferences is not a
59 +license to be rude.
60 +
61 +Disputes over package rights must be handled respectfully, according
62 +to the terms described in the [Disputes Policy][disputes].
63 +There is never a good reason to be rude over package name disputes.
64 +
65 +Any spamming, trolling, flaming, baiting, or other attention-stealing
66 +behavior is not welcome, and will not be tolerated.
67 +
68 +Harassing other users of the Service is never tolerated, whether via
69 +public or private media.
70 +
71 +Avoid using offensive or harassing package names, nicknames, or other
72 +identifiers that might detract from a friendly, safe, and welcoming
73 +environment for all.
74 +
75 +Harassment includes, but is not limited to: harmful or prejudicial
76 +verbal or written comments related to gender identity, sexual
77 +orientation, ability, ethnicity, religion, age, physical
78 +appearance, body size, race, or similar personal characteristics;
79 +inappropriate use of nudity, sexual images, and/or sexually explicit
80 +language in public spaces; threats of physical or non-physical harm;
81 +deliberate intimidation, stalking or following; harassing photography
82 +or recording; sustained disruption of talks or other events;
83 +inappropriate physical contact; and unwelcome sexual attention.
84 +
85 +## Acceptable Use
86 +
87 +The Service administrators reserve the right to make judgment calls
88 +about what is and isn't appropriate in published packages, package names,
89 +user and organization names, and other public content. Package that
90 +violates the npm Service's
91 +[Acceptable Use][acceptable-use]
92 +rules including its
93 +[Acceptable Content][acceptable-content]
94 +rules will be deleted, at the discretion of npm.
95 +
96 +## Reporting Violations of this Code of Conduct
97 +
98 +Please select the method of contact you think is most appropriate for
99 +the form of violation:
100 +
101 +* For urgent security issues, please open a ticket at <https://npmjs.com/support>.
102 + Requests to un-publish packages are not usually considered urgent security
103 + issues, as it is possible to [un-publish a package][unpublish]
104 + within 24 hours of its first publish. Any publicly published package
105 + is [immediately replicated to thousands of third-party mirrors](http://blog.npmjs.org/post/101934969510/oh-no-i-accidentally-published-private-data-to),
106 + so any confidential information contained in a package should be considered
107 + immediately compromised.
108 +
109 +* If you believe someone is harassing you or is demonstrating
110 + some other form of malicious or inappropriate behavior, open a support
111 + ticket at https://npmjs.com/support. If this is the initial report of a problem,
112 + please include as much detail as possible. It is easiest for us
113 + to address issues when we have more context.
114 +
115 +* If you have concerns about a potential copyright violation,
116 + please refer to our [Copyright Policy][dmca]
117 + and take action as recommended by that policy.
118 +
119 +* If you think a package or other content is "squatting" on a name,
120 + follow the process described in the
121 + [Disputes Policy][disputes].
122 +
123 +For any other issues, or if in doubt, [contact support](https://npmjs.com/support).
124 +
125 +
126 +## Consequences
127 +
128 +All content published to the Service, including user account
129 +credentials, is hosted at the sole discretion of the npm
130 +administrators.
131 +
132 +Unacceptable behavior from any community member, including sponsors,
133 +employees, customers, or others with decision-making authority, will
134 +not be tolerated.
135 +
136 +Anyone asked to stop unacceptable behavior is expected to comply
137 +immediately.
138 +
139 +If a community member engages in unacceptable behavior, the npm
140 +administrators may take any action they deem appropriate, up to and
141 +including a temporary ban or permanent expulsion from the community
142 +without warning (and without refund in the case of a paid event or
143 +service).
144 +
145 +## Addressing Grievances
146 +
147 +If you feel you have been falsely or unfairly accused of violating
148 +this Code of Conduct, you should notify npm, Inc. We will do our best
149 +to ensure that your grievance is handled appropriately.
150 +
151 +In general, we will choose the course of action that we judge as being
152 +most in the interest of fostering a safe and friendly community.
153 +
154 +## Contact Info
155 +
156 +Please open a support ticket at <https://npmjs.com/support> if you need to
157 +report a problem or address a grievance related to an abuse report.
158 +
159 +You are also encouraged to contact us if you are curious about
160 +something that might be "on the line" between appropriate and
161 +inappropriate content. We are happy to provide guidance to help you
162 +be a successful part of our community.
163 +
164 +## Changes
165 +
166 +This is a living document and may be updated from time to time.
167 +Please refer to the [git history for this
168 +document](https://github.com/npm/documentation/blob/main/content/policies/conduct.mdx)
169 +to view the changes.
170 +
171 +## Credit and License
172 +
173 +This Code of Conduct borrows heavily from the Stumptown Syndicate
174 +[Citizen's Code of Conduct](http://citizencodeofconduct.org/), and the
175 +[Rust Project Code of
176 +Conduct](https://www.rust-lang.org/conduct.html).
177 +
178 +This document may be reused under a [Creative Commons
179 +Attribution-ShareAlike
180 +License](https://creativecommons.org/licenses/by-sa/4.0/).
181 +
182 +[disputes]: /policies/disputes
183 +[acceptable-use]: /policies/open-source-terms#acceptable-use
184 +[acceptable-content]: /policies/open-source-terms#acceptable-content
185 +[unpublish]: /policies/unpublish
186 +[dmca]: /policies/dmca
\ No newline at end of file
content/policies/crawlers.mdx new
+11
@@ -0,0 +1,11 @@
1 +---
2 +title: Crawler policy
3 +---
4 +
5 +npm's full public dataset is available via the [public registry](https://docs.npmjs.com/misc/registry). Using CouchDB replication, you can get a full copy of all metadata, and it is acceptable within our terms of use to download copies of tarballs for inspection or experimentation.
6 +
7 +npm's [website](https://www.npmjs.com) also has package metadata available. We allow this content to be indexed by commercial crawlers such as GoogleBot. At our discretion, we also allow experimental crawlers to access the site, as long as they keep their request velocity to 1 request per second or less. At that velocity, indexing all packages would take 3 days, so if you want a full copy of our metadata it is always going to be faster to access the data via replication, which takes only an hour or two to provide full data and will thereafter automatically stay in sync.
8 +
9 +If you do not wish to install CouchDB to manage replication, we provide [open source software](https://github.com/npm/concurrent-couch-follower) that makes it easy to sync to the registry's public feed.
10 +
11 +If you attempt to access package metadata by high-velocity crawling of the npm website, we reserve the right to rate-limit or ban your IP, user-agent or both.
content/policies/disputes.mdx new
+159
@@ -0,0 +1,159 @@
1 +---
2 +title: Dispute Resolution
3 +---
4 +
5 +This document describes the steps that you should take to resolve module
6 +name disputes with other npm publishers. It also describes special steps
7 +you should take about names you think [infringe your trademarks](#trademarks).
8 +
9 +This document is additive to the guidelines in the
10 +[npm Code of Conduct][conduct] and
11 +[npm Open-Source terms][open-source-terms].
12 +Nothing in this document should be interpreted to contradict any aspect
13 +of the npm Code of Conduct or Open-Source Terms.
14 +
15 +## tl;dr
16 +
17 +1. Open a support ticket at <https://npmjs.com/support>
18 +1. Explain why you require a package, org, or username transferred
19 +1. Support will address your request. Please note submitting a report does not
20 + guarantee the transfer of a package, org, or username.
21 +
22 +## When to use this process
23 +
24 +This process is an excellent way to:
25 +
26 +* Adopt a package created from your project, published by someone else
27 +* Report a deliberately misleading or confusing package name
28 +
29 +This process does not apply if the package violates our
30 +[Terms of Use][open-source-terms],
31 +in particular our
32 +[Acceptable Use][acceptable-use]
33 +and [Acceptable Content][acceptable-content]
34 +rules, or our [Code of Conduct][conduct].
35 +Those documents refer to this one to resolve cases of "squatting"; see
36 +below.
37 +
38 +If you see bad behavior or content you believe is unacceptable, refer to
39 +the Code of Conduct for guidelines on
40 +[reporting violations][violations].
41 +**You are never expected to resolve abusive behavior on your own.**
42 +**We are here to help.**
43 +
44 +## When not to use this process
45 +
46 +We are not currently accepting dispute requests to "adopt an abandoned
47 +package" or "Report Squatting" as we re-evaluate and update the overall
48 +dispute process.
49 +
50 +## Beginning the process
51 +
52 +### Packages
53 +
54 +To dispute a package called `foo`, follow these steps:
55 +
56 +1. Open a support ticket at <https://npmjs.com/support>, indicating that
57 + you would like to start the process to request ownership of the `foo`
58 + package. Please explain the why you believe the package should be transferred.
59 + You will get an automated reply from npm support to your email address.
60 +1. Support will address your request. Please note submitting a report does not
61 + guarantee the transfer of a package.
62 +
63 +### Organizations
64 +
65 +To dispute an organization name, follow these steps:
66 +
67 +1. Open a support ticket at <https://npmjs.com/support>, indicating that
68 + you dispute an organization name. Include the name of the organization,
69 + e.g. `@foo`. Please explain the why you believe the Organizations should
70 + be transferred. You will get an automated reply from npm support to your
71 + email address.
72 +1. Support will address your request. Please note submitting a report does not
73 + guarantee the transfer of an organization.
74 +
75 +### User names
76 +
77 +To dispute a user name, follow these steps:
78 +
79 +1. Open a support ticket at <https://npmjs.com/support>, indicating that
80 + you dispute a user name. Include the name of the user account,
81 + e.g. `@foo`. Please explain why you believe the Username should be
82 + transferred. You will get an automated reply from npm support to your
83 + email address.
84 +1. Support will address your request. Please note submitting a report does not
85 + guarantee the transfer of a user name.
86 +
87 +## Trademarks
88 +
89 +If you think another npm publisher is infringing your trademark, such
90 +as by using a confusingly similar package, org, or user account name,
91 +open a support ticket at <https://npmjs.com/support> with a link to
92 +the package, org, or user account page on <https://npmjs.com>. Attach
93 +a copy of your trademark registration certificate.
94 +
95 +If we see that the user, org, or package publisher is intentionally
96 +misleading others by misusing your registered mark without permission,
97 +we will transfer the account, org, or package name to you. Otherwise, we
98 +will contact the relevant user and ask them to clear up any confusion with
99 +changes to their user account page, or page, or package `README` file.
100 +
101 +Use of npm's own trademarks is covered by our Trademark Policy at
102 +<https://docs.npmjs.com/trademark>.
103 +
104 +## Changes
105 +
106 +This is a living document and may be updated from time to time.
107 +Please refer to the [git history for this
108 +document](https://github.com/npm/documentation/blob/main/content/policies/disputes.mdx)
109 +to view the changes.
110 +
111 +## Definitions
112 +
113 +### Squatting
114 +
115 +It is against npm's
116 +[Terms of Use][acceptable-content]
117 +to publish a package, register a user name or an organization name
118 +simply for the purposes of reserving it for future use.
119 +
120 +We do not pro-actively scan the registry for squatted packages, so
121 +the fact that a name is in use does not mean we consider it valid.
122 +The standards for what we consider squatting depend on what is being
123 +squatted:
124 +
125 +#### Packages
126 +
127 +Package names are considered squatted if the package has no genuine
128 +function.
129 +
130 +#### Organizations
131 +
132 +Organization names are considered squatted if there are no packages
133 +published within a reasonable time. If an organization is a paid
134 +organization, it may have private packages that are invisible to
135 +third parties. For privacy reasons, we cannot reveal whether or not
136 +an organization has private packages, so a paid organization will
137 +never be considered squatted.
138 +
139 +#### User names
140 +
141 +We are extremely unlikely to transfer control of a user name, as it
142 +is totally valid to be an npm user and never publish any packages:
143 +for instance, you might be part of an organization or need read-only
144 +access to private packages.
145 +
146 +## License
147 +
148 +Copyright (C) npm, Inc., All rights reserved
149 +
150 +This document may be reused under a [Creative Commons
151 +Attribution-ShareAlike
152 +License](https://creativecommons.org/licenses/by-sa/4.0/).
153 +
154 +[conduct]: /policies/conduct
155 +[open-source-terms]: /policies/open-source-terms
156 +[acceptable-use]: /policies/open-source-terms#acceptable-use
157 +[acceptable-content]: /policies/open-source-terms#acceptable-content
158 +[violations]: /policies/conduct#reporting-violations-of-this-code-of-conduct
159 +[trademark]: /policies/trademark
\ No newline at end of file
content/policies/dmca.mdx new
+145
@@ -0,0 +1,145 @@
1 +---
2 +title: Copyright Policy
3 +---
4 +
5 +This policy describes how we at npm, Inc., the company behind npmjs.com
6 +and the npm public registry, respond to claims that materials user
7 +have submitted to our service infringe copyright. In short, we follow
8 +the Digital Millennium Copyright Act, or DMCA.
9 +
10 +## What's the DMCA?
11 +
12 +The DMCA is a United States federal law that sets up a formal process
13 +for reports of copyright infringement by our users, called takedown
14 +notices. It also sets up a process for disputing takedown notices
15 +by sending counter notices. The law protects us from liability for
16 +infringement by our users when we follow these steps. It also makes
17 +those who abuse the takedown and dispute processes liable for damage
18 +they cause.
19 +
20 +Many online service providers like us handle great numbers of takedown
21 +notices and counter notices. Often, the whole process takes place
22 +online, with the help of automated tools. However, the legal claims
23 +and documents involved remain very serious. Please approach the
24 +process accordingly.
25 +
26 +## Should I send a takedown notice?
27 +
28 +If you aren't absolutely sure both that you own copyright, and that a
29 +user' material on our service infringes, speak to an attorney before
30 +sending a DMCA takedown notice. Knowing, material misrepresentations
31 +about infringement in a takedown notice can make you liable to us,
32 +the person you allege infringes, copyright owners, and licensees,
33 +all for significant damages, including costs and attorneys' fees.
34 +A lawyer can help you decide if you should file a takedown notice,
35 +and if so, help you prepare it correctly. We cannot.
36 +
37 +## How do I send a takedown notice?
38 +
39 +Send takedown notices to our agent. You can find their contact
40 +information [below](#agent).
41 +
42 +Per United States Code, title 17, section 512(c)(3), your takedown
43 +notice must have:
44 +
45 +1. A physical or electronic signature of a person authorized to act
46 + on behalf of the copyright owner.
47 +
48 +2. Identification of the copyrighted work you claim is been infringed.
49 +
50 +3. Identification of the infringing material to be removed.
51 +
52 +4. Contact information, preferably an email address, that we can
53 + use to reach you.
54 +
55 +5. Your statement of good faith belief that use of the material in
56 + the manner complained of is not authorized by the copyright owner,
57 + its agent, or the law.
58 +
59 +6. Your statement that the information in your notice is accurate.
60 +
61 +7. Your statement, under penalty of perjury, that you are authorized
62 + to act on behalf of the owner of the copyright allegedly infringed.
63 +
64 +## How do we respond to takedown notices?
65 +
66 +When we receive a valid takedown notice, we forward a copy to the
67 +[Lumen Database](https://lumendatabase.org/) and remove or restrict
68 +access to allegedly infringing material. We then try to contact
69 +the user that submitted the material, to notify them that we have
70 +removed or restricted access to the material, provide them a copy of
71 +the takedown notice, and direct them to this policy.
72 +
73 +When appropriate, we suspend or terminate the accounts of users who
74 +repeatedly infringe copyright through our service.
75 +
76 +## Should I dispute a takedown?
77 +
78 +If you aren't absolutely sure that your material doesn't infringe
79 +copyright, speak to an attorney before sending a DMCA counter notice.
80 +Knowing, material misrepresentations about mistaken removal or access
81 +restriction can make you liable to us, the one who filed the takedown
82 +notice, copyright owners, and licensees, all for significant damages,
83 +including costs and attorneys' fees. A lawyer can help you decide
84 +if you should file a counter notice, and if so, help you prepare
85 +it correctly. We cannot.
86 +
87 +## How do I dispute a takedown?
88 +
89 +Do _not_ resubmit material to our service that we removed or restricted
90 +in response to a takedown notice. If you do this, we will suspend
91 +or terminate your account.
92 +
93 +Send counter notices to our agent. You can find their contact
94 +information [below](#agent).
95 +
96 +Per United States Code, title 17, section 512(g)(3), your counter
97 +notice must have:
98 +
99 +1. Your physical or electronic signature.
100 +
101 +2. Identification of the material removed access-restricted, and
102 + where it was available via our service before we removed or
103 + restricted access to it.
104 +
105 +3. Your statement, under penalty of perjury, that you have a good
106 + faith belief that the material was removed or disabled as a result
107 + of a mistake or misidentification of the material.
108 +
109 +4. Your name, address, and telephone number.
110 +
111 +5. Your statement that you consent to the jurisdiction of the Federal
112 + District Court for the judicial district in which your address
113 + is located, or if outside the United Sates, for any any judicial
114 + district in which we may be found.
115 +
116 +6. Your statement that you will accept service of process from the
117 + person who provided the takedown notice, or their agent.
118 +
119 +## How do we respond to counter notices?
120 +
121 +When we receive a valid counter-notice, we forward a copy to the
122 +person who filed the takedown notice. If they don't notify us in ten
123 +business days that they are seeking a court order to prevent further
124 +infringement, we may replace or restore access to to the material
125 +we removed.
126 +
127 +## Where do I send notice?
128 +
129 +Send all takedown notices and counter notices to:
130 +
131 +You can also send an email notification to
132 +[copyright@npmjs.com](mailto:copyright@npmjs.com). You may include an
133 +attachment if you like, but please also include a plain-text version of
134 +your letter in the body of your message.
135 +
136 +If you must send your notice by physical mail, you can do that too, but
137 +it will take substantially longer for us to receive and respond to it.
138 +Notices we receive via plain-text email have a much faster turnaround
139 +than PDF attachments or physical mail. If you still wish to mail us
140 +your notice, our physical address is:
141 +
142 +GitHub, Inc
143 +Attn: DMCA Agent
144 +88 Colin P Kelly Jr St
145 +San Francisco, CA. 94107
content/policies/domains.mdx new
+47
@@ -0,0 +1,47 @@
1 +---
2 +title: What domains does npm use?
3 +---
4 +
5 +How can you tell an email or domain really belongs to npm and isn't a phishing attempt? Here's a full list:
6 +
7 +## Active domains
8 +
9 +* registry.npmjs.org - the official, default npm registry
10 +* npmjs.com - the domain of our website and any email from us
11 +* npm.im - a short domain used to redirect to packages, e.g. npm.im/express
12 +* npm.me - a short domain used for redirects in marketing campaigns, ads, etc.
13 +* npm.red - a domain used for staging our website and registry in development
14 +
15 +## Formerly used
16 +
17 +* npmcamp.com, npm.camp - for our conference
18 +
19 +## Idle
20 +
21 +We own these but don't use them for anything (yet).
22 +
23 +* npmjs.net
24 +* npm.rocks
25 +* npm.tips
26 +* npm.xyz
27 +* npm.computer
28 +* npm.technology
29 +* npm.today
30 +* npm.email
31 +* npm.mn
32 +* npm.so
33 +
34 +## Changes
35 +
36 +This is a living document and may be updated from time to time.
37 +Please refer to the [git history for this
38 +document](https://github.com/npm/documentation/blob/main/content/policies/domains.mdx)
39 +to view the changes.
40 +
41 +## License
42 +
43 +Copyright (C) npm, Inc., All rights reserved
44 +
45 +This document may be reused under a [Creative Commons
46 +Attribution-ShareAlike
47 +License](https://creativecommons.org/licenses/by-sa/4.0/).
content/policies/index.mdx new
+8
@@ -0,0 +1,8 @@
1 +---
2 +policies
3 +---
4 +
5 +These are updated from time to time. Their sources are stored in a git
6 +repository at [https://github.com/npm/documentation/content/policies](https://github.com/npm/documentation/content/policies).
7 +
8 +<Index />
content/policies/npm-license.mdx new
+266
@@ -0,0 +1,266 @@
1 +---
2 +title: npm License
3 +---
4 +
5 +Copyright (c) npm, Inc. and Contributors
6 +All rights reserved.
7 +
8 +npm is released under the Artistic License 2.0, subject to additional terms
9 +that are listed below.
10 +
11 +The text of the npm License follows and the text of the additional terms
12 +follows the Artistic License 2.0 terms:
13 +
14 +
15 +--------
16 +
17 +
18 +The Artistic License 2.0
19 +
20 +Copyright (c) 2000-2006, The Perl Foundation.
21 +
22 +Everyone is permitted to copy and distribute verbatim copies
23 +of this license document, but changing it is not allowed.
24 +
25 +Preamble
26 +
27 +This license establishes the terms under which a given free software
28 +Package may be copied, modified, distributed, and/or redistributed.
29 +The intent is that the Copyright Holder maintains some artistic
30 +control over the development of that Package while still keeping the
31 +Package available as open source and free software.
32 +
33 +You are always permitted to make arrangements wholly outside of this
34 +license directly with the Copyright Holder of a given Package. If the
35 +terms of this license do not permit the full use that you propose to
36 +make of the Package, you should contact the Copyright Holder and seek
37 +a different licensing arrangement.
38 +
39 +Definitions
40 +
41 + "Copyright Holder" means the individual(s) or organization(s)
42 + named in the copyright notice for the entire Package.
43 +
44 + "Contributor" means any party that has contributed code or other
45 + material to the Package, in accordance with the Copyright Holder's
46 + procedures.
47 +
48 + "You" and "your" means any person who would like to copy,
49 + distribute, or modify the Package.
50 +
51 + "Package" means the collection of files distributed by the
52 + Copyright Holder, and derivatives of that collection and/or of
53 + those files. A given Package may consist of either the Standard
54 + Version, or a Modified Version.
55 +
56 + "Distribute" means providing a copy of the Package or making it
57 + accessible to anyone else, or in the case of a company or
58 + organization, to others outside of your company or organization.
59 +
60 + "Distributor Fee" means any fee that you charge for Distributing
61 + this Package or providing support for this Package to another
62 + party. It does not mean licensing fees.
63 +
64 + "Standard Version" refers to the Package if it has not been
65 + modified, or has been modified only in ways explicitly requested
66 + by the Copyright Holder.
67 +
68 + "Modified Version" means the Package, if it has been changed, and
69 + such changes were not explicitly requested by the Copyright
70 + Holder.
71 +
72 + "Original License" means this Artistic License as Distributed with
73 + the Standard Version of the Package, in its current version or as
74 + it may be modified by The Perl Foundation in the future.
75 +
76 + "Source" form means the source code, documentation source, and
77 + configuration files for the Package.
78 +
79 + "Compiled" form means the compiled bytecode, object code, binary,
80 + or any other form resulting from mechanical transformation or
81 + translation of the Source form.
82 +
83 +
84 +Permission for Use and Modification Without Distribution
85 +
86 +(1) You are permitted to use the Standard Version and create and use
87 +Modified Versions for any purpose without restriction, provided that
88 +you do not Distribute the Modified Version.
89 +
90 +
91 +Permissions for Redistribution of the Standard Version
92 +
93 +(2) You may Distribute verbatim copies of the Source form of the
94 +Standard Version of this Package in any medium without restriction,
95 +either gratis or for a Distributor Fee, provided that you duplicate
96 +all of the original copyright notices and associated disclaimers. At
97 +your discretion, such verbatim copies may or may not include a
98 +Compiled form of the Package.
99 +
100 +(3) You may apply any bug fixes, portability changes, and other
101 +modifications made available from the Copyright Holder. The resulting
102 +Package will still be considered the Standard Version, and as such
103 +will be subject to the Original License.
104 +
105 +
106 +Distribution of Modified Versions of the Package as Source
107 +
108 +(4) You may Distribute your Modified Version as Source (either gratis
109 +or for a Distributor Fee, and with or without a Compiled form of the
110 +Modified Version) provided that you clearly document how it differs
111 +from the Standard Version, including, but not limited to, documenting
112 +any non-standard features, executables, or modules, and provided that
113 +you do at least ONE of the following:
114 +
115 + (a) make the Modified Version available to the Copyright Holder
116 + of the Standard Version, under the Original License, so that the
117 + Copyright Holder may include your modifications in the Standard
118 + Version.
119 +
120 + (b) ensure that installation of your Modified Version does not
121 + prevent the user installing or running the Standard Version. In
122 + addition, the Modified Version must bear a name that is different
123 + from the name of the Standard Version.
124 +
125 + (c) allow anyone who receives a copy of the Modified Version to
126 + make the Source form of the Modified Version available to others
127 + under
128 +
129 + (i) the Original License or
130 +
131 + (ii) a license that permits the licensee to freely copy,
132 + modify and redistribute the Modified Version using the same
133 + licensing terms that apply to the copy that the licensee
134 + received, and requires that the Source form of the Modified
135 + Version, and of any works derived from it, be made freely
136 + available in that license fees are prohibited but Distributor
137 + Fees are allowed.
138 +
139 +
140 +Distribution of Compiled Forms of the Standard Version
141 +or Modified Versions without the Source
142 +
143 +(5) You may Distribute Compiled forms of the Standard Version without
144 +the Source, provided that you include complete instructions on how to
145 +get the Source of the Standard Version. Such instructions must be
146 +valid at the time of your distribution. If these instructions, at any
147 +time while you are carrying out such distribution, become invalid, you
148 +must provide new instructions on demand or cease further distribution.
149 +If you provide valid instructions or cease distribution within thirty
150 +days after you become aware that the instructions are invalid, then
151 +you do not forfeit any of your rights under this license.
152 +
153 +(6) You may Distribute a Modified Version in Compiled form without
154 +the Source, provided that you comply with Section 4 with respect to
155 +the Source of the Modified Version.
156 +
157 +
158 +Aggregating or Linking the Package
159 +
160 +(7) You may aggregate the Package (either the Standard Version or
161 +Modified Version) with other packages and Distribute the resulting
162 +aggregation provided that you do not charge a licensing fee for the
163 +Package. Distributor Fees are permitted, and licensing fees for other
164 +components in the aggregation are permitted. The terms of this license
165 +apply to the use and Distribution of the Standard or Modified Versions
166 +as included in the aggregation.
167 +
168 +(8) You are permitted to link Modified and Standard Versions with
169 +other works, to embed the Package in a larger work of your own, or to
170 +build stand-alone binary or bytecode versions of applications that
171 +include the Package, and Distribute the result without restriction,
172 +provided the result does not expose a direct interface to the Package.
173 +
174 +
175 +Items That are Not Considered Part of a Modified Version
176 +
177 +(9) Works (including, but not limited to, modules and scripts) that
178 +merely extend or make use of the Package, do not, by themselves, cause
179 +the Package to be a Modified Version. In addition, such works are not
180 +considered parts of the Package itself, and are not subject to the
181 +terms of this license.
182 +
183 +
184 +General Provisions
185 +
186 +(10) Any use, modification, and distribution of the Standard or
187 +Modified Versions is governed by this Artistic License. By using,
188 +modifying or distributing the Package, you accept this license. Do not
189 +use, modify, or distribute the Package, if you do not accept this
190 +license.
191 +
192 +(11) If your Modified Version has been derived from a Modified
193 +Version made by someone other than you, you are nevertheless required
194 +to ensure that your Modified Version complies with the requirements of
195 +this license.
196 +
197 +(12) This license does not grant you the right to use any trademark,
198 +service mark, tradename, or logo of the Copyright Holder.
199 +
200 +(13) This license includes the non-exclusive, worldwide,
201 +free-of-charge patent license to make, have made, use, offer to sell,
202 +sell, import and otherwise transfer the Package with respect to any
203 +patent claims licensable by the Copyright Holder that are necessarily
204 +infringed by the Package. If you institute patent litigation
205 +(including a cross-claim or counterclaim) against any party alleging
206 +that the Package constitutes direct or contributory patent
207 +infringement, then this Artistic License to you shall terminate on the
208 +date that such litigation is filed.
209 +
210 +(14) Disclaimer of Warranty:
211 +THE PACKAGE IS PROVIDED BY THE COPYRIGHT HOLDER AND CONTRIBUTORS "AS
212 +IS' AND WITHOUT ANY EXPRESS OR IMPLIED WARRANTIES. THE IMPLIED
213 +WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR
214 +NON-INFRINGEMENT ARE DISCLAIMED TO THE EXTENT PERMITTED BY YOUR LOCAL
215 +LAW. UNLESS REQUIRED BY LAW, NO COPYRIGHT HOLDER OR CONTRIBUTOR WILL
216 +BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
217 +DAMAGES ARISING IN ANY WAY OUT OF THE USE OF THE PACKAGE, EVEN IF
218 +ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
219 +
220 +
221 +--------
222 +
223 +
224 +The following additional terms shall apply to use of the npm software, the npm
225 +website, the npm repository and any other services or products offered by npm,
226 +Inc.:
227 +
228 +"Node.js" trademark Joyent, Inc. npm is not officially part of the Node.js
229 +project, and is neither owned by nor affiliated with Joyent, Inc.
230 +
231 +"npm" and "The npm Registry" are owned by npm, Inc. All rights reserved.
232 +
233 +Modules published on the npm registry are not officially endorsed by npm, Inc.
234 +or the Node.js project.
235 +
236 +Data published to the npm registry is not part of npm itself, and is the sole
237 +property of the publisher. While every effort is made to ensure accountability,
238 +there is absolutely no guarantee, warrantee, or assertion expressed or implied
239 +as to the quality, fitness for a specific purpose, or lack of malice in any
240 +given npm package. Packages downloaded through the npm registry are
241 +independently licensed and are not covered by this license.
242 +
243 +Additional policies relating to, and restrictions on use of, npm products and
244 +services are available on the npm website. All such policies and restrictions,
245 +as updated from time to time, are hereby incorporated into this license
246 +agreement. By using npm, you acknowledge your agreement to all such policies
247 +and restrictions.
248 +
249 +If you have a complaint about a package in the public npm registry, and cannot
250 +resolve it with the package owner, please
251 +[contact support](https://npmjs.com/support) and explain the situation.
252 +See the [npm Dispute Resolution policy](https://github.com/npm/documentation/blob/main/content/policies/disputes.mdx) for more details.
253 +
254 +Any data published to The npm Registry (including user account information) may
255 +be removed or modified at the sole discretion of the npm server administrators.
256 +
257 +"npm Logo" contributed by Mathias Pettersson and Brian Hammond,
258 +use is subject to https://docs.npmjs.com/trademark
259 +
260 +"Gubblebum Blocky" font
261 +Copyright (c) by Tjarda Koster, https://jelloween.deviantart.com
262 +included for use in the npm website and documentation,
263 +used with permission.
264 +
265 +This program uses several Node modules contained in the node_modules/
266 +subdirectory, according to the terms of their respective licenses.
content/policies/open-source-terms.mdx new
+514
@@ -0,0 +1,514 @@
1 +---
2 +title: npm Open-Source Terms
3 +---
4 +<!-- TODO: Replace last-updated date for every published change -->
5 +These npm Open Source terms of use (these _Terms_) govern access to
6 +and use of <https://www.npmjs.com> (the _Website_) as well as the
7 +"npm Public Registry" at <https://registry.npmjs.org> (the _Public
8 +Registry_), and the discussion forum at <https://npm.community>
9 +(_npm.community_). npm, Inc. (_npm_) operates each of those
10 +services. These terms refer to all of them together as _npm Open
11 +Source_.
12 +
13 +npm last updated these npm Open Source Terms on
14 +December 16, 2019.
15 +You can review prior versions at
16 +<https://github.com/npm/documentation/blob/main/content/policies/open-source-terms.mdx>.
17 +
18 +## Important Terms
19 +
20 +***These Terms include a number of important provisions that affect your
21 +rights and responsibilities, such as the disclaimers in "Disclaimers",
22 +limits on npm's liability to you in "Limits on Liability", and an
23 +agreement to arbitrate disputes individually in "Arbitration".***
24 +
25 +## Other Terms
26 +
27 +npm offers additional, paid services (_Paid Services_) that are subject
28 +to additional terms:
29 +
30 +- Additional terms for npm Paid Services are available at
31 + [https://docs.npmjs.com/policies/private-terms][private-terms].
32 +
33 +npm Open Source and any Paid Services you may agree to use are together
34 +called _npm Services_ throughout these Terms.
35 +
36 +## Legal Agreement
37 +
38 +You may only access or use npm Services by agreeing to these Terms.
39 +If npm adds any additional functionality to npm Services, you must
40 +agree to these Terms to use that new functionality, too. You show your agreement
41 +with npm on these Terms by creating a user account (your _Account_)
42 +or by accessing or using npm Services without creating an account.
43 +The agreement between you and npm is a legally binding contract (this
44 +_Agreement_).
45 +
46 +## Changes
47 +
48 +npm may change these Terms and the additional terms for Paid Services
49 +in the future. npm will post changes on the Website with a new "last
50 +updated" date. If you have an Account, npm will notify you of changes
51 +by email to the address provided for your Account, by a message on the
52 +Website, or both. If you do not have an account, npm may notify you of
53 +changes by a general announcement via the Website, but it is up to you
54 +to check for changes to these Terms. After receiving notice of changes
55 +to these Terms, you must accept those changes to continue using npm
56 +Services. You accept changes to these Terms by continuing to use npm
57 +Services. npm may change, suspend, or discontinue npm Services at any
58 +time without notice or liability to you.
59 +
60 +## npm Policies
61 +
62 +npm respects your privacy and limits use and sharing of information
63 +about you collected by npm Services. The privacy policy at
64 +[https://docs.npmjs.com/policies/privacy][privacy](the _Privacy Policy_)
65 +describes these policies. npm will abide by the Privacy Policy and honor
66 +the privacy settings that you choose via npm Services.
67 +
68 +npm respects the exclusive rights of copyright holders and responds
69 +to notifications about alleged infringement via npm Services per
70 +the copyright policy at [https://docs.npmjs.com/dmca][dmca] (the
71 +_Copyright Policy_).
72 +
73 +npm resolves disputes about package names, user names, and organization
74 +names in the Public Registry per the policy at
75 +[https://docs.npmjs.com/disputes][disputes] (_Dispute Policy_). This
76 +includes "package squatting".
77 +
78 +Use of all npm Services is governed by the code of conduct at
79 +[https://docs.npmjs.com/conduct][conduct] (_Code of Conduct_).
80 +
81 +npm permits use of npm trademarks per the policy at
82 +[https://docs.npmjs.com/trademark][trademark].
83 +
84 +## Use of npm Open Source
85 +
86 +Subject to these Terms, npm grants you permission to use npm Open
87 +Source. That permission is not exclusive to you, and you cannot transfer
88 +it to anyone else.
89 +
90 +Your permission to use npm Open Source entitles you to do the following:
91 +
92 +1. You may search for, download, publish, and manage packages of
93 + computer code (_Packages_) in the Public Registry, and otherwise
94 + interact with the Public Registry, via the command-line tool
95 + published by npm at <https://www.github.com/npm/npm> (the _CLI_).
96 +
97 +2. You may search for, download, publish, and manage Packages using
98 + software other than CLI via application programming interfaces that
99 + npm publicly documents or makes available for public use (_Public
100 + APIs_).
101 +
102 +3. You may search for and manage Packages in the Public Registry, and
103 + otherwise interact with the Public Registry, via the Website.
104 +
105 +4. You may update and manage your Account via the Website.
106 +
107 +5. You may visit, create an account for, and participate in,
108 + discussions on npm.community.
109 +
110 +## Conditions
111 +
112 +Your permission to use npm Open Source, as well as any permission you
113 +may have to use Paid Services, are subject to the following conditions:
114 +
115 +1. You must be at least 13 years of age to use npm Services.
116 +
117 +2. You may not use npm Services after npm says you may not, such as by
118 + disabling your Account.
119 +
120 +3. You must use npm Services only in accordance with "Acceptable Use".
121 +
122 +4. You may access and use data about the security of Packages, such
123 + as vulnerability reports, audit status reports, and supplementary
124 + security documentation, only for your own personal or internal
125 + business purposes. You may _not_ provide others access to, copies
126 + of, or use of npm data about the security of Packages, directly
127 + or as part of other products or services.
128 +
129 +## Acceptable Use
130 +
131 +1. You will abide by the
132 + [Code of Conduct][conduct] and the
133 + [Dispute Policy][disputes].
134 +
135 +2. You will not submit material to npm as a package or in any other
136 + form that violates npm's _Acceptable Content_, described below.
137 +
138 +3. You will not disclose information that you do not have the right to
139 + disclose, such as confidential information of others.
140 +
141 +4. You will not copy or share any personally identifiable information of
142 + any other person without their specific permission.
143 +
144 +5. You will not violate any applicable law.
145 +
146 +6. You will not use or attempt to use another person's Account without
147 + their specific permission.
148 +
149 +7. You will not buy, sell, or otherwise trade in user names,
150 + organization names, names for _Packages_, or any other names
151 + reserved on _npm Services_, for money or other compensation.
152 +
153 +8. You will not use _npm Services_' ability to send e-mail to send
154 + advertisements, chain letters, or other solicitations.
155 +
156 +9. You will not automate access to, use, or monitor the Website, such
157 + as with a web crawler, browser plug-in or add-on, or other computer
158 + program that is not a web browser. You may replicate data from the
159 + Public Registry using the Public APIs per this Agreement.
160 +
161 +10. You will not use npm Services to send email to distribution lists,
162 + newsgroups, or group mail aliases.
163 +
164 +11. You will not falsely imply that you are affiliated with or endorsed
165 + by npm.
166 +
167 +12. You will not operate illegal schemes, such as pyramid schemes, via
168 + npm Services.
169 +
170 +13. You will not deep-hyperlink to images or other non-hypertext content
171 + served by npm Services.
172 +
173 +14. You will not remove any marking indicating proprietary ownership
174 + from any material got via npm Services.
175 +
176 +15. You will not display any portion of the Website via an HTML IFRAME.
177 +
178 +16. You will not disable, avoid, or circumvent any security or access
179 + restrictions of npm Services, or access parts of npm Services not
180 + intended for access by you.
181 +
182 +17. You will not strain infrastructure of npm Services with an
183 + unreasonable volume of requests, or requests designed to impose an
184 + unreasonable load on IT systems underlying npm Services. This rule
185 + is intentionally loose, to give npm the flexibility it needs to keep
186 + npm Services working for the user community as a whole. But to draw
187 + one clear line, under no circumstances are five million requests to
188 + npm Services in a single month-long period by any single individual,
189 + organization, or group of affiliated companies remotely reasonable. If
190 + you have a special need to make lots and lots of requests, [our
191 + sales team](mailto:sales@npmjs.com) can help.
192 +
193 +18. You will not encourage or assist any other person in violation of
194 + "Acceptable Use".
195 +
196 +## Acceptable Content
197 +
198 +Administrators at npm reserve the right to delete content hosted on
199 +the npm Services that they deem unacceptable. Unacceptable content
200 +can take the form of a package, a README file, a user or organization
201 +name, or any other content submitted to npm Services. A few examples
202 +of unacceptable content:
203 +
204 +1. Content that is illegal, offensive, or otherwise harmful. This includes
205 + content that is harassing, inappropriate, or abusive.
206 +
207 +2. Content in violation of law, infringing the intellectual property
208 + rights of others, violating the privacy or other rights of others,
209 + or in violation of any agreement with a third party. This includes
210 + code that violates a public license for others' work.
211 +
212 +3. Content containing malicious computer code, such as computer viruses,
213 + computer worms, rootkits, back doors, or spyware. This includes content
214 + submitted for research purposes. Tools designed and documented explicitly to
215 + assist in security research are acceptable, but exploits and malware that
216 + use the npm registry as a deployment or delivery vector are not.
217 +
218 +4. Packages that are not functionally compatible with the npm
219 + command-line client. For example, a "package" cannot simply be
220 + a PNG or JPEG image, a movie file, or a text document uploaded
221 + directly to the registry. Using the Public Registry as a general purpose database is not allowed.
222 +
223 +5. Content that exists only to "reserve" a name, whether a package name,
224 + user name, or organization name. The
225 + [Dispute Policy][disputes] governs
226 + how npm handles such cases of "squatting".
227 +
228 +To find out how to report violations of Acceptable Content, refer to the
229 +[Code of Conduct][conduct].
230 +
231 +## Commercial Content
232 +
233 +The npm Public Registry is about Packages. All manner of
234 +useful Packages are welcome, from hobby projects to
235 +competitive products, enterprise infrastructure and tooling
236 +to the latest fun hack or work of software art.
237 +
238 +At the same time, the npm Public Registry, the Website, and
239 +important conventions like `README` go beyond just code.
240 +Developers use all of those channels to communicate more
241 +broadly about code, who is developing it, why, and how.
242 +
243 +That communication is important, and welcome, so long as it
244 +respects that the npm Public Registry, the website, and npm
245 +Open Source more generally remain neutral. You are free to
246 +use npm Open Source for commercial projects, to advance your
247 +career, and for other business purposes. But you may not
248 +leverage content or system conventions to make the npm
249 +Public Registry, Website, or CLI put business before code.
250 +
251 +These kinds of commercial content are generally acceptable
252 +in `README` files and other documentation:
253 +
254 +1. Credits, acknowledgments, attributions, and other
255 + recognitions of contributions to Packages.
256 +
257 +2. Information on how to pay, donate to, and otherwise
258 + support Package development, Package developers, and
259 + Package steward organizations.
260 +
261 +3. Logos from, and links to, organizations developing,
262 + stewarding, or sponsoring Package development.
263 +
264 +4. Information on paid products and services related to
265 + Packages, such as enhanced versions, add-ons, commercial
266 + license terms, training, integration, or support.
267 +
268 +These kinds of commercial content generally _aren't_
269 +acceptable:
270 +
271 +1. `README`, `package.json`, or other content displaying
272 + advertisements.
273 +
274 +2. Packages that display ads at runtime, on installation,
275 + or at other stages of the software development
276 + lifecycle, such as via [npm
277 + scripts](https://docs.npmjs.com/misc/scripts). Packages
278 + with code that can be used to display ads are fine.
279 + Packages that themselves display ads are not.
280 +
281 +3. Packages that function primarily as ads, with only
282 + placeholder or negligible code, data, and other
283 + technical content.
284 +
285 +These examples are just examples. npm will continue to
286 +apply its judgment when deciding what content is acceptable.
287 +npm will continue to expect you to apply your own judgment
288 +when choosing what you share and how.
289 +
290 +## Enforcement of Acceptable Use
291 +
292 +npm may investigate and prosecute violations of this Agreement to the
293 +fullest legal extent. npm may notify and cooperate with law enforcement
294 +authorities in prosecuting violations of this Agreement.
295 +
296 +## Your Account
297 +
298 +You must create and log into an Account to access features of some npm
299 +Services, including npm Open Source.
300 +
301 +To create an Account, you must provide certain information about
302 +yourself, as required by the account creation form on the Website or the
303 +CLI. If you create an Account, you will provide, at a minimum, a valid
304 +email address. You will keep that email address up-to-date. You will
305 +not impersonate any other individual. You may delete your Account at any
306 +time by [contacting support](https://npmjs.com/support).
307 +
308 +You will be responsible for all action taken using your account, whether
309 +authorized by you or not, until you either close your account or give
310 +npm notice that the security of your Account has been compromised.
311 +You will notify npm immediately if you suspect the security of your
312 +Account has been compromised. You will select a secure password for your
313 +Account. You will keep your password secret.
314 +
315 +npm may restrict, suspend, or terminate your Account according to the
316 +Copyright Policy, if npm reasonably believes that you are in breach of
317 +these Terms, or if npm reasonably believes that you have misused npm
318 +Services.
319 +
320 +## Your Content
321 +
322 +Nothing in this Agreement gives npm any ownership rights in intellectual
323 +property that you share with npm Services, such as your Account
324 +information or any Packages you share with npm Services (_Your
325 +Content_). Nothing in this Agreement gives you any ownership rights in
326 +npm intellectual property provided via npm Services, like software,
327 +documentation, trademarks, service marks, logotypes, or other
328 +distinguishing graphics.
329 +
330 +Between you and npm, you remain solely responsible for Your Content. You
331 +will not wrongly imply that Your Content is sponsored or approved by
332 +npm. npm will not be obligated to store, maintain, or provide copies of
333 +your content, except per the Privacy Policy.
334 +
335 +npm may remove Your Content from npm Services without notice if npm
336 +suspects Your Content was submitted or used in violation of "Acceptable
337 +Use", as well as per the Copyright Policy.
338 +
339 +Your Content belongs to you. You decide whether and how to license it.
340 +But at a minimum, you license npm to provide Your Content to users
341 +of npm Services when you share Your Content. That special license
342 +allows npm to copy, publish, and analyze Your Content, and to share
343 +its analyses with others. npm may run computer code in Your Content to
344 +analyze it, but npm's special license alone does not give npm the right
345 +to run code for its functionality in npm products or services.
346 +
347 +When Your Content is removed from npm Services,
348 +whether by you or npm, npm's special license ends when the last copy
349 +disappears from npm's backups, caches, and other systems. Other
350 +licenses, such as open source licenses, may continue after Your Content
351 +is removed. Those licenses may give others, or npm itself, the right to
352 +share Your Content with npm Services again.
353 +
354 +Others who receive Your Content via npm Services may violate the terms
355 +on which you license Your Content. You agree that npm will not be liable
356 +to you for those violations or their consequences.
357 +
358 +## Feedback
359 +
360 +npm welcomes your feedback and suggestions for npm Services. You agree
361 +that npm will be free to act on feedback and suggestions you provide
362 +without further notice, consent, or payment. You will not submit
363 +feedback or suggestions that you consider confidential or proprietary.
364 +
365 +## Indemnity
366 +
367 +You will indemnify npm, its officers, directors, employees,
368 +representatives, and agents, and hold them harmless for, all liability,
369 +expenses, damages, and costs from any third-party claims, demands,
370 +lawsuits, or other proceedings alleging that Your Content, your use
371 +of npm Services, or both, violate the intellectual property right of
372 +a third party, this Agreement, or applicable law. You will not settle
373 +any such proceeding without the prior written consent of npm. npm will
374 +notify you of any such proceeding it becomes aware of.
375 +
376 +## Disclaimers
377 +
378 +***Use of npm Services is at your sole risk. npm Services are provided
379 +on an "as is" and "as available" basis. npm expressly disclaims all
380 +warranties of any kind, whether express, implied, or statutory,
381 +including implied warranties of title, noninfringement, merchantability,
382 +and fitness for a particular purpose.***
383 +
384 +***npm makes no warranty that npm Services will meet your requirements,
385 +operate in an uninterrupted, timely, secure, or error-free manner, or
386 +that errors in npm Services will be corrected.***
387 +
388 +***You receive material via npm Services at your sole risk. You will be
389 +solely responsible for any damage to your computer system and network,
390 +as well as any data loss that may result from use of npm Services or
391 +material received via npm Services.***
392 +
393 +npm Services may provide information and software that is inaccurate,
394 +incomplete, misleading, illegal, offensive, or otherwise harmful. npm
395 +may, but does not promise to, review content provided by npm Services.
396 +
397 +npm Services provide information about ownership and licensing of
398 +Packages, as provided by those Packages' publishers. That information
399 +may be wrong. npm cannot and does not provide legal advice.
400 +
401 +### Third-Party Services
402 +
403 +npm Services may hyperlink to and integrate with third-party
404 +applications, websites, and other services. You decide whether and how
405 +to use and interact with such services. npm does not make any warranty
406 +regarding such services or content they may provide, and will not be
407 +liable to you for any damages related to such services. Use of such
408 +third-party services may be governed by other terms and privacy notices
409 +that are not part of this Agreement and are not controlled by npm.
410 +
411 +## Limits on Liability
412 +
413 +***Neither npm nor any third-party service provider used by npm to
414 +provide npm Services will, under any circumstances, be liable to you
415 +for any indirect, incidental, consequential, special, or exemplary
416 +damages related to your use of npm Services or this Agreement, whether
417 +based on breach of contract, breach of warranty, tort (including
418 +negligence, product liability, or otherwise), or any other pecuniary
419 +loss, and whether or not npm has been advised of the possibility of such
420 +damages.***
421 +
422 +***To the maximum extent permitted by law, npm's liability to you for
423 +any damages related to this Agreement, for any one or more causes and
424 +regardless of the form of action, will not exceed $50.***
425 +
426 +Some jurisdictions do not allow exclusion of certain warranties or
427 +limits on liability for incidental or consequential damages. Some of
428 +"Disclaimers" and "Limits on Liability" may not apply to you.
429 +
430 +## Termination
431 +
432 +Either you or npm may terminate this Agreement at any time with notice
433 +to the other.
434 +
435 +On termination of this Agreement, your permission to use npm Open
436 +Source, as well any permission you may have to access Paid Services
437 +under additional terms, also terminate.
438 +
439 +The following provisions survive termination of this Agreement: "Your
440 +Content", "Feedback", "Indemnity", "Disclaimers", "Limits on Liability",
441 +and "General Terms". Users of npm Services may continue to copy and
442 +share Your Content after termination of this Agreement.
443 +
444 +## Payment Terms
445 +
446 +There is no charge for use of npm Open Source. If you use Paid Services
447 +from npm, our Paid Services Terms at [https://docs.npmjs.com/policies/private-terms][private-terms]
448 +apply.
449 +
450 +## General Terms
451 +
452 +If a provision of this Agreement is unenforceable as written, but could
453 +be changed to make it enforceable, that provision should be modified to
454 +the minimum extent necessary to make it enforceable. Otherwise, that
455 +provision should be removed.
456 +
457 +You may not assign this Agreement. npm may assign this Agreement to any
458 +affiliate of npm, any third party that obtains control of npm, or any
459 +third party that purchases assets of npm relating to npm Services. Any
460 +purported assignment of rights in breach of this provision is void.
461 +
462 +Neither the exercise of any right under this Agreement, nor waiver of
463 +any breach of this Agreement, waives any other breach of this Agreement.
464 +
465 +This Agreement, together with the additional terms for Paid Services
466 +and npm software that you and npm agree to, embody all the terms of
467 +agreement between you and npm about npm Services. This Agreement
468 +supersedes any other agreements about npm Services, written or not.
469 +
470 +## Disputes
471 +
472 +The law of the State of California will govern any dispute, including
473 +any legal proceedings, relating to this Agreement or your use of npm
474 +Services (a _Dispute_).
475 +
476 +You and npm will seek injunctions related to this agreement only in
477 +state or federal court in San Francisco, California. Neither you nor npm
478 +will object to jurisdiction, forum, or venue in those courts.
479 +
480 +***Other than to seek an injunction, you and npm will resolve any
481 +Dispute by binding American Arbitration Association arbitration.
482 +Arbitration will follow the AAA's Commercial Arbitration Rules and
483 +Supplementary Procedures for Consumer Related Disputes. Arbitration will
484 +happen in San Francisco, California. You will settle any Dispute as an
485 +individual, and not as part of a class action or other representative
486 +proceeding, whether as the plaintiff or a class member. No arbitrator
487 +will consolidate any Dispute with any another arbitration without npm's
488 +permission.***
489 +
490 +Any arbitration award will include costs of the arbitration, reasonable
491 +attorneys' fees, and reasonable costs for witnesses. You or npm can
492 +enter arbitration awards in any court with jurisdiction.
493 +
494 +## Notices and Questions
495 +
496 +You may send notice to npm and questions about the terms governing npm
497 +products and services to [legal@npmjs.com](mailto:legal@npmjs.com) or
498 +by mail to:
499 +
500 +GitHub, Inc
501 +Attn: npm Legal Department
502 +88 Colin P Kelly Jr St
503 +San Francisco, CA. 94107
504 +
505 +npm may send you notice using the email address you provide for your
506 +Account or by posting a message to the homepage or your Account page
507 +on the Website.
508 +
509 +[private-terms]: /policies/private-terms
510 +[conduct]: /policies/conduct
511 +[trademark]: /policies/trademark
512 +[disputes]: /policies/disputes
513 +[dmca]: /policies/dmca
514 +[privacy]: /policies/privacy
\ No newline at end of file
content/policies/orgs-plan.mdx new
+35
@@ -0,0 +1,35 @@
1 +---
2 +title: npm Orgs Payment Plan
3 +---
4 +
5 +This npm Orgs Payment Plan (this _Payment Plan_) supplements
6 +the terms for npm Open Source offered by npm, Inc. (_npm_) at
7 +[https://docs.npmjs.com/policies/open-source-terms][open-source-terms] (_npm Open Source
8 +Terms_), as well as the terms for npm Paid Services (_npm Paid Services_)
9 +at [https://docs.npmjs.com/policies/private-terms][private-terms] (_npm
10 +Paid Services Terms_). This Payment Plan governs payment for
11 +_Orgs_ and use of npm Paid Services by user
12 +accounts added as members of those Orgs.
13 +
14 +This Payment Plan was last updated on
15 +August 6, 2018.
16 +You can review prior versions at
17 +<https://github.com/npm/documentation/blob/main/content/policies/orgs-plan.mdx>.
18 +
19 +Under this Payment Plan, you may create one or more Orgs.
20 +
21 +You will pay a minimum of $7.00 via your Payment Card when you create
22 +an Org, and thereafter on the same day every month (your
23 +_Billing Day_), until you delete the Org. This minimum payment
24 +entitles you to a single member of the Org (a _New Paid Services
25 +User_). You will pay $7.00 via your Payment Card per each additional
26 +New Paid Services User that you add to an Org, counted and
27 +billed on your Billing Day.
28 +
29 +Note that the npm Paid Services Terms require everyone using npm Paid
30 +Services to have an Account of their own, added under a Payment Plan.
31 +You must add a New Paid Services User to an Org for each
32 +person who will use npm Paid Services under this Payment Plan.
33 +
34 +[open-source-terms]: /policies/open-source-terms
35 +[private-terms]: /policies/private-terms
\ No newline at end of file
content/policies/privacy.mdx new
+642
@@ -0,0 +1,642 @@
1 +---
2 +title: Privacy Questions and Answers
3 +---
4 +
5 +This notice describes how [npm, Inc.](https://www.npmjs.com/about), or _npm_ for short, collects and uses data about you.
6 +
7 +Skip to:
8 +- [What's most important?](#important)
9 +- [How does npm collect data about me?](#collection)
10 +- [What data does npm collect about me, and why?](#data)
11 +- [Does npm share data about me with others?](#sharing)
12 +- [How can I make choices about data collection?](#choice)
13 +- [Where does npm keep data about me?](#locality)
14 +- [How does npm handle data under the EU General Data Protection Regulation?](#gdpr)
15 +- [How does npm handle data under the California Consumer Privacy Act?](#ccpa)
16 +- [How can I see what data is publicly available about me?](#access)
17 +- [How can I change data about me?](#change)
18 +- [What is npm's policy on unpublishing packages?](#forgotten)
19 +- [How does npm notify others about published data that's erased?](#erasure-notice)
20 +- [What happens if npm merges with or is bought by another company?](#merge)
21 +- [What are npm's information practices regarding information belonging to children?](#children)
22 +- [Who can I contact about npm and my privacy?](#contact)
23 +- [How can I find out about changes?](#changes)
24 +
25 +## [What's most important?](#important)
26 +
27 +That depends on your personal situation, which is why you should read on
28 +and decide for yourself. But at a minimum, absolutely every npm user
29 +should understand:
30 +
31 +*The npm public registry is for making software available to everyone
32 +online.*
33 +
34 +But: *Software comes from people, and says something about us.*
35 +
36 +So: *Think carefully about what packages to publish, what data you put
37 +in those packages, and what others might do with that data.*
38 +
39 +When you create an account, certain contact information is displayed
40 +publicly in the npm platform. And when you upload a package, your name
41 +and contact information may become associated with that package.
42 +
43 +If you find yourself in a jam,
44 +[open a support ticket](https://npmjs.com/support).
45 +
46 +
47 +## [How does npm collect data about me?](#collection)
48 +
49 +npm collects data about you:
50 +
51 +- when you use the [npm command](https://www.npmjs.com/package/npm),
52 + the [npx command](https://www.npmjs.com/package/npx) or another
53 + program to access the [npm public registry](https://registry.npmjs.org/),
54 + [Enterprise registries that npm hosts](https://www.npmjs.com/enterprise),
55 + [private packages](https://www.npmjs.com/features),
56 + such as when you're publishing a software package, and APIs for
57 + functionality like account and permissions management
58 +
59 +- when you browse the npm website, [npmjs.com](https://www.npmjs.com/)
60 +
61 +- when you use either the npm command or the website to create an npm account,
62 + update your account, and sign up for npm services
63 +
64 +- when you send support, privacy, legal, and other requests to npm
65 +
66 +- when working with and researching current and potential customers
67 +
68 +When researching potential customers, npm staff sometimes search the
69 +public World Wide Web or paid business databases. Otherwise, npm
70 +doesn't buy or receive data about you from data brokers or other
71 +private services.
72 +
73 +npm may inadvertently collect data about you if it is included in
74 +software packages that you or others upload.
75 +
76 +## [What data does npm collect about me, and why?](#data)
77 +
78 +### [npm collects data about how you use npm software and registries](#usage-data)
79 +
80 +When you use the `npm` command, the `npx` command, or other software to work
81 +with the npm public registry, an Enterprise registry that npm hosts, or
82 +private packages, npm logs data that might be identified to you:
83 +
84 +- a random, unique identifier, called `npm-session`, for each time you
85 + run commands like `npm install`
86 +
87 +- the names and versions of your project's dependencies, their
88 + dependencies, and so on, that come from the npm public registry,
89 + [but not of other dependencies, like Git
90 + dependencies](https://docs.npmjs.com/cli/audit)
91 +
92 +- the versions of Node.js, the npm command, and the operating system
93 + you are using
94 +
95 +- an `npm-in-ci` header, showing whether the command was run on a
96 + continuous integration server
97 +
98 +- the scope of the package for which you ran `npm install`, as an
99 + `npm-scope` header
100 +
101 +- a `referrer` header that shows the command you ran, with any file or
102 + directory paths redacted
103 +
104 +- data about the software you're using to access the registry, such
105 + as the `User-Agent` string
106 +
107 +- network request data, such as the date and time, your IP address,
108 + and the URL
109 +
110 +npm uses this data to:
111 +
112 +- fulfill your requests, such as by sending the packages you ask for
113 +
114 +- send you alerts about security vulnerabilities that may affect the
115 + software you're building, when you run `npm install` or `npm audit`
116 +
117 +- keep registries working quickly and reliably
118 +
119 +- debug and develop the `npm` command and other software
120 +
121 +- defend registries from abuse and technical attacks
122 +
123 +- compile statistics on package usage and popularity
124 +
125 +- prepare reports on trends in the developer community
126 +
127 +- improve search results on the website
128 +
129 +- recommend packages that may be relevant to your work
130 +
131 +### [npm collects data about how you use the website.](#website-data)
132 +
133 +When you visit [www.npmjs.com](https://www.npmjs.com/),
134 +[docs.npmjs.com](https://docs.npmjs.com/), and other npm
135 +websites, npm uses cookies, server logs, and other methods to collect
136 +data about what pages you visit, and when. npm also collects technical
137 +information about the software and computer you use, such as:
138 +
139 +- your IP address
140 +
141 +- your preferred language
142 +
143 +- the web browser software you use
144 +
145 +- the kind of computer you use
146 +
147 +- the website that referred you
148 +
149 +npm uses data about how you use the website to:
150 +
151 +- optimize the website, so that it's quick and easy to use
152 +
153 +- diagnose and debug technical errors
154 +
155 +- defend the website from abuse and technical attacks
156 +
157 +- compile statistics on package popularity
158 +
159 +- compile statistics on the kinds of software and computers visitors
160 + use
161 +
162 +- compile statistics on visitor searches and needs, to guide
163 + development of new website pages and functionality
164 +
165 +- decide who to contact about about product announcements, service
166 + changes, and new features
167 +
168 +### [npm collects account data](#account-data)
169 +
170 +Many features of npm services require an npm account. For example, you
171 +must have an npm account to publish packages to the npm public registry.
172 +
173 +To create an npm account, npm requires a working email address and an
174 +available user name. npm uses this data to provide you access to
175 +features and identify you across npm services, publicly and within npm.
176 +
177 +You do not have to give your personal or legal name to create an npm
178 +account. You can use a pseudonym instead. You can also open more than
179 +one account.
180 +
181 +If you sign up for an account, then npm will publish account data for
182 +the whole world to see on user pages [like this one](https://www.npmjs.com/~kemitchell).
183 +npm also publishes account data through the npm public registry,
184 +which is available for everyone to see, and Enterprise registries that npm hosts for others to
185 +find with commands like npm owner ls tap.
186 +
187 +If you give npm a personal name or names on social media like
188 +[GitHub](https://github.com/) and
189 +[Twitter](https://twitter.com/) through the website, like
190 +when you include this on your profile or user page, npm publishes that
191 +data along with the email address and user name for the account. You
192 +don't have to give npm a personal name or any social media names, and
193 +you can remove this data at any time by updating your user page.
194 +
195 +npm uses your email to:
196 +
197 +- notify you about packages published using your account
198 +
199 +- reset your password and help keep your account secure
200 +
201 +- add metadata to packages that you publish
202 +
203 +- contact you in special circumstances related to your account or packages
204 +
205 +- contact you about support requests
206 +
207 +- contact you about legal requests, like DMCA takedown requests and privacy complaints
208 +
209 +- announce new npm product offerings, service changes, and features
210 +
211 +- send you tips about how to better use free and paid services
212 +
213 +- send you messages about paid services you might want
214 +
215 +### [npm collects package data](#package-data)
216 +
217 +When you use npm publish or other software to publish packages to the
218 +npm public registry, an Enterprise registry that npm hosts, or as a
219 +private package, npm collects the contents of the package, plus
220 +[metadata](https://en.wikipedia.org/wiki/Metadata),
221 +including your account data. Other npm users may also publish packages
222 +that include data about you, such as the fact that you contributed code
223 +to a package.
224 +
225 +npm uses data in packages to provide those packages to you and others
226 +who request them:
227 +
228 +- When you publish a package to the npm public registry, or change a
229 + package from private to public, npm makes the package and metadata
230 + available to everyone, online.
231 +
232 +- When you publish a package to an Enterprise registry that npm hosts,
233 + or as a private package, npm makes all of that data available to
234 + other users according to how the registry or the private packages
235 + account is configured. You may be able to configure who can access
236 + the package, or that may be up to others, such as the
237 + administrator of your company's Enterprise registry.
238 +
239 +Making package data available to others allows them to download, build
240 +on, and depend on your work.
241 +
242 +### [npm collects payment card data](#payment-data)
243 +
244 +To sign up for paid services, npm requires your payment card data. npm
245 +itself does not collect or store enough information to charge your card
246 +itself. Rather, [Stripe](https://stripe.com/) collects
247 +that data on npm's behalf, and gives npm security tokens that allow npm
248 +to create charges and subscriptions.
249 +
250 +npm uses your payment card data only to charge for npm services.
251 +
252 +npm instructs [Stripe](https://stripe.com/) to store your
253 +payment card data only as long as you use paid npm services.
254 +
255 +
256 +### [npm collects data about correspondence](#contact-data)
257 +
258 +npm collects data about you when you send npm support requests, legal
259 +complaints, privacy inquiries, and business inquiries. Those data
260 +usually include your name and email address, and may include your
261 +company or other affiliation.
262 +
263 +npm uses contact data to:
264 +
265 +- respond to you
266 +
267 +- compile aggregate statistics about correspondence
268 +
269 +- train support staff and other npm personnel
270 +
271 +- review the performance of npm personnel who respond
272 +
273 +- defend npm from legal claims
274 +
275 +### [npm collects data about use of npm.community](#forum-data)
276 +
277 +npm collects data about visits, user accounts, and forum data on
278 +[npm.community](https://npm.community/), the discussion
279 +forum for users of npm products and services. npm uses data from
280 +npm.community to collaborate with the development community, and to
281 +inform development decisions about the command-line interface and other
282 +software.
283 +
284 +## [Does npm share data about me with others?](#sharing)
285 +
286 +npm shares account data with others as [mentioned in the section about
287 +account data](#account-data).
288 +
289 +npm shares package data with others as [mentioned in the section about
290 +package data](privacy#package-data).
291 +
292 +npm publishes posts and other content you submit to [npm.community](https://npm.community/).
293 +
294 +npm does not sell information about you to others. However, npm uses
295 +services provided by other companies to provide npm services. The types
296 +of service providers that npm uses include:
297 +
298 +- Companies that enable us to offer features on our website, such as to display your avatar
299 +
300 +- Companies that facilitate the efficient distribution of content
301 +
302 +- Cloud computing platforms and services that host our discussion forums
303 +
304 +- Services that assist with the detection of spam, scams, abuse
305 + others, or other violations of our [terms of service][privacy]
306 +
307 +- Payment processors
308 +
309 +- Platforms to help us receive, manage, and respond to support requests
310 +
311 +- Platforms for internal communication
312 +
313 +### [npm uses cookies](#cookies)
314 +
315 +npm's website only uses cookies strictly necessary to provide, optimize
316 +and secure the website. For example, we use them to keep you logged in,
317 +remember your preferences, authenticate your device for security
318 +purposes, analyze your use of the service, compile statistical reports,
319 +and provide information for future development of npm. The website uses
320 +internal cookies for analytics purposes, not any third-party analytics
321 +or service providers.
322 +
323 +By using the website, you agree that we can place these types of
324 +cookies on your computer or device. If you disable your browser or
325 +device’s ability to accept these cookies, you will not be able to log
326 +in or use the website.
327 +
328 +## [How can I make choices about data collection?](#choice)
329 +
330 +You choose what data the npm publish command includes in package data.
331 +You can use an [.npmignore](https://docs.npmjs.com/files/package.json#files)
332 +file in your package to keep specific files out of the package. You can
333 +also use a [files list in package.json
334 +files](https://docs.npmjs.com/files/package.json#files) to
335 +instruct npm to include only specific files that you name, in addition
336 +to standard files like `README` files, `LICENSE` files, and package.json.
337 +
338 +To double check the data that you will share in a package that you plan
339 +to publish, run the `npm publish --dry-run` command. If you are running
340 +an older version of the npm command, run the npm pack command to create a
341 +[tarball](https://en.wikipedia.org/wiki/Tar_(computing%29),
342 +then check its contents, such as with `tar tvzf $tarball`.
343 +
344 +To publish a package to the npm public registry, npm's terms of service
345 +require you to [license npm to share it][your-content].
346 +If a package is made public, it is available for everyone online to see.
347 +However, your [choice of public license for your package](https://docs.npmjs.com/files/package.json#license)
348 +may affect what others can do with data about you in your package.
349 +
350 +npm does not respond to the [Do Not Track HTTP header](https://en.wikipedia.org/wiki/Do_Not_Track).
351 +
352 +## [Where does npm keep data about me?](#locality)
353 +
354 +npm stores account data, data about website use, data about registry
355 +use, and private packages on servers in the United States of America.
356 +metadata about those packages worldwide, via content delivery
357 +networks.
358 +
359 +npm stores package data published to Enterprise registries that npm
360 +hosts, plus metadata about them, in cloud computing zones of customers' choosing.
361 +
362 +By using the npm platform, you consent to the collection and storage of
363 +your data as outlined in this section.
364 +
365 +## [How does npm handle data under the EU General Data Protection Regulation?](#gdpr)
366 +
367 +
368 +npm respects privacy rights under [Regulation (EU) 2016/679](http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv:OJ.L_.2016.119.01.0001.01.ENG),
369 +the European Union's General Data Protection Regulation (GDPR). npm
370 +processes "Personal Data" on the following legal bases: (1) with your
371 +consent; (2) as necessary to perform our agreement to provide our
372 +services; and (3) as necessary for our legitimate interests in providing
373 +our services where those interests do not override your fundamental
374 +rights and freedom related to data privacy. Information we collect may
375 +be transferred to, and stored and processed in, the United States or any
376 +other country in which we or our affiliates or subcontractors maintain
377 +facilities, as described above.
378 +
379 +If you reside in the EEA, Switzerland, or United Kingdom, you are
380 +entitled to certain rights, like the right to:
381 +
382 +- complain about our data collection or processing actions with the
383 + supervisor authority concerned. You can find a list of data
384 + protection authorities [here](http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm).
385 +
386 +- access to information held about you.
387 +
388 +- ask us to correct or amend inaccurate or incomplete information we have about you.
389 +
390 +- ask us to erase data that under certain circumstances, like (1) when
391 + it is no longer necessary for the purpose for which it was
392 + collected, (2) you withdraw consent and no other legal basis for
393 + processing exists, or (3) you believe your fundamental rights to
394 + data privacy and protection outweigh our legitimate interest in
395 + continuing the processing.
396 +
397 +- request that we restrict our processing if we are processing your
398 + data based on legitimate interests or the performance of a task in
399 + the public interest as an exercise of official authority
400 + (including profiling); using your data for direct marketing
401 + (including profiling); or processing your data for purposes of
402 + scientific or historical research and statistics.
403 +
404 +When you exercise your rights, npm may need to verify your identity and
405 +provide us with information before we access records containing your
406 +information. If you want to exercise your rights, please contact npm by
407 +[opening a support ticket](https://npmjs.com/support). We
408 +may have a reason under the law why we do not have to comply with your
409 +request or may comply with it in a more limited way than you
410 +anticipated. If we do, we will explain that to you in our response.
411 +
412 +## [How does npm handle data under the California Consumer Privacy Act?](#ccpa)
413 +
414 +npm respects the rights of California residents under the [California
415 +Consumer Privacy Act](https://www.oag.ca.gov/privacy/ccpa)
416 +(CCPA)]. Where we collect information that is subject to the
417 +CCPA, that information we collect and your rights are described below.
418 +
419 +Categories of personal information we collect:
420 +
421 +- _Personal Identifiers_:
422 +
423 + - Name and email address when you create an account. You will also
424 + be asked to create a username and we will assign one or more
425 + unique identifiers to your profile. We use this information to
426 + provide our services, respond to your requests, and send
427 + information to you.
428 +
429 + - We also collect your social media handle and basic account
430 + information if you provide it to us or interact with our
431 + services, such as our help desk, through social media.
432 +
433 + - We collect your payment information through our service
434 + provider, Stripe, as described above.
435 +
436 +- _Internet or Other Electronic Network Activity Information_: device
437 + identifiers such as IP address and user agent; the assigned unique
438 + IDs in cookies (as described below); information about how you
439 + arrived at and navigated through our Services.
440 +
441 +- _Geolocation Data:_ We do not collect your specific longitude and
442 + latitude. However, we do collect imprecise location (e.g., your IP address).
443 +
444 +- _Professional or employment-related information:_ If you apply for
445 + employment with us, information about your employment history.
446 +
447 +- _Education information:_ If you apply for employment with us,
448 + information about your educational history.
449 +
450 +We may collect any other information about you contained in software
451 +packages uploaded to our site, as described above under the "npm
452 +collects package data" section. We also collect the contents of your
453 +communications with us, e.g., when you submit a question to us through
454 +a web form or comments to us on social media.
455 +
456 +We may disclose any of the categories of personal information listed
457 +above and use them for the above-listed purposes or for other business
458 +or operational purposes compatible with the context in which the
459 +personal information was collected. Our disclosures of personal
460 +information include disclosures to our "service providers," which are
461 +companies that we engage for business purposes to conduct activities
462 +on our behalf. The categories of service providers with whom we share
463 +information and the services they provide are described below.
464 +
465 +Rights under CCPA:
466 +
467 +- _Access/Right to Know_: You have the right to request access to
468 + personal information we collected about you and information
469 + regarding the source of that personal information, the purposes
470 + for which we collect it, and the third parties and service
471 + providers with whom we share it.
472 +
473 +- _Deletion_: You have the right to request that we erase data we have
474 + collected from you. Please note that we may have a reason to deny
475 + your deletion request or delete data in a more limited way than
476 + you anticipated, e.g., because of a legal obligation to retain it.
477 +
478 +To exercise your rights above, you can
479 +[open a support ticket](https://npmjs.com/support). When we
480 +process your request, we must verify your identity by asking you to
481 +(1) provide personal identifiers that we can match against information
482 +we may have collected from you previously; and (2) confirm your
483 +request using the email stated in the request.
484 +
485 +Opt-out of sale:
486 +
487 +California residents have the right to request that we stop "selling"
488 +their personal information. A "sale" of personal information is
489 +defined broadly: "selling, renting, releasing, disclosing,
490 +disseminating, making available, transferring, or otherwise
491 +communicating orally, in writing, or by electronic or other means, a
492 +consumer's personal information by the business to another business or
493 +a third party for monetary or other valuable consideration." We do not
494 +sell your information as defined by the CCPA.
495 +
496 +Please note that your right to opt out does not apply to our sharing
497 +of personal information with service providers, who are parties we
498 +engage to perform a function on our behalf and are contractually
499 +obligated to use the Personal Information only for that function.
500 +
501 +We may also disclose information to other entities who are not listed
502 +here when required by law or to protect our Company or other persons,
503 +as described in our Privacy Policy.
504 +
505 +
506 +## [How can I see what data is publicly available about me?](#access)
507 +
508 +You can access your account data at any time by visiting your account
509 +page on [www.npmjs.com](https://www.npmjs.com/). Your
510 +account page also lists all the packages published under your account or
511 +other accounts.
512 +
513 +You can access package data by downloading the packages, as long as
514 +they're public or you have permission to access them.
515 +
516 +You can see metadata about packages by running npm info $package, or by
517 +accessing the appropriate [registry's
518 +API](https://github.com/npm/registry/tree/master/docs).
519 +Registry APIs provide metadata in standard [JSON](https://www.json.org/)
520 +format, and packages as
521 +[tarballs](https://en.wikipedia.org/wiki/Tar_(computing)).
522 +
523 +## [How can I change data about me?](#change)
524 +
525 +You can change your personal account data and payment card data at any
526 +time by visiting your account settings page on
527 +[www.npmjs.com](https://www.npmjs.com/). You can change
528 +account and payment data for Enterprise by [contacting support](https://npmjs.com/support).
529 +
530 +You can close your npm account at any time by e-mailing
531 +[contacting support](https://npmjs.com/support). Closing
532 +your account removes the profile from the public registry but does not
533 +automatically erase packages published under your account. We may retain
534 +some data about you internally even where you close your account.
535 +
536 +npm's [unpublish policy][unpublish]
537 +determines when you can erase packages from the npm public registry. The
538 +unpublish policy strikes a difficult balance between the purpose of
539 +publishing and hosting packages, others' reliance on what has been made
540 +public, and individual rights and freedoms.
541 +
542 +If another user improperly publishes personal data about you, in a
543 +package or otherwise,
544 +[open a support ticket](https://npmjs.com/support).
545 +
546 +Please note that while [npm publishes notices about published data
547 +that's been erased](#erasure-notice),
548 +npm can't make everyone who has downloaded published package data or
549 +account data erase that data on your behalf. Choosing a public
550 +license, such as an open source software license,
551 +may encourage and allow storage, distribution, and use of package data
552 +indefinitely. Nearly all popular open source software licenses actually
553 +require preserving personal data that attributes the software to you,
554 +such as copyright notices, as a condition of permission for the
555 +software.
556 +
557 +
558 +## [What is npm's policy on unpublishing packages?](#forgotten)
559 +
560 +Please see [our policy on "unpublishing" packages][unpublish] or
561 +[our terms of service][open-source-terms] for more
562 +information on erasing packages].
563 +
564 +If you accidentally publish a package that threatens your privacy, or
565 +discover someone else has published a package that does,
566 +[open a support ticket](https://npmjs.com/support).
567 +npm can and will take down packages in specific, exceptional situations
568 +to protect you, especially if others violate your privacy. Using npm to
569 +violate others' privacy is against our [terms of service][open-source-terms].
570 +
571 +
572 +## [How does npm notify others about published data that's erased?](#erasure-notice)
573 +
574 +npm takes a few steps to notify others who may be copying data from the
575 +npm public registry that published data has been erased:
576 +
577 +- npm publishes new placeholder versions of some erased packages, with
578 + `README` files that mention the package has been erased, and why.
579 +
580 +- npm's [registry APIs](https://github.com/npm/registry/tree/master/docs),
581 + special software services that others use to copy data from the
582 + npm public registry, send update messages about packages that have
583 + been erased.
584 +
585 +
586 +## [What happens if npm merges with or is bought by another company?](#merge)
587 +
588 +We may transfer to another entity or its affiliates or service providers
589 +some or all information about you in connection with, or during
590 +negotiations of, any merger, acquisition, sale of assets or any line of
591 +business, change in ownership control, or financing transaction. We
592 +cannot promise that an acquiring party or the merged entity will have
593 +the same privacy practices or treat your information the same as
594 +described in this Policy.
595 +
596 +
597 +## [What are npm's information practices regarding information belonging to children?](#children)
598 +
599 +npm's site and services are intended for users age sixteen and older.
600 +npm does not knowingly collect information from children. If we discover
601 +that we have inadvertently collected information from anyone younger
602 +than the age of 16, we will delete that information.
603 +
604 +## [Who can I contact about npm and my privacy?](#contact)
605 +
606 +Please [open a support ticket](https://npmjs.com/support). You may also
607 +contact our Data Protection Officer directly.
608 +
609 +Our United States HQ:
610 +
611 +GitHub Data Protection Officer
612 +Attention: npm Data Protection
613 +88 Colin P. Kelly Jr. St.
614 +San Francisco, CA 94107
615 +United States
616 +
617 +or our EU Office:
618 +
619 +GitHub BV
620 +Vijzelstraat 68-72
621 +1017 HL Amsterdam
622 +The Netherlands
623 +
624 +## [How can I find out about changes?](#changes)
625 +
626 +This version of npm's privacy questions and answers took effect June 3, 2020.
627 +
628 +npm will announce the next version on the [npm blog](https://blog.npmjs.org/).
629 +In the meantime, npm may update [its contact information](#contact)
630 +by updating the page at
631 +[https://docs.npmjs.com/privacy][privacy],
632 +without an announcement. npm may change how it announces changes in
633 +future privacy versions.
634 +
635 +You can review the history of changes in [the Git repository for npm's
636 +public policies](https://github.com/npm/documentation/blob/main/content/policies/privacy.mdx).
637 +
638 +[terms]: /policies/terms
639 +[privacy]: /policies/privacy
640 +[open-source-terms]: /policies/open-source-terms
641 +[unpublish]: /policies/unpublish
642 +[your-content]: /policies/open-source-terms#your-content)
\ No newline at end of file
content/policies/private-terms.mdx new
+83
@@ -0,0 +1,83 @@
1 +---
2 +title: npm Paid Services Terms
3 +---
4 +
5 +These npm Paid Services Terms of Use (these _npm Paid Services Terms_)
6 +supplement the terms for npm Open Source offered by npm, Inc.
7 +(_npm_) at <https://docs.npmjs.com/open-source-terms> (_npm Open
8 +Source Terms_). They govern access to and use of _npm Paid Services_,
9 +including but not limited to the products known as _npm Solo_ and
10 +_npm Orgs_, the private package storage, delivery,
11 +organization management, and access control features of
12 +<https://www.npmjs.com> (the _Website_) and the npm public registry
13 +at <https://registry.npmjs.org> (the _Public Registry_). These are
14 +collectively called the _Paid Services_.
15 +
16 +These npm Paid Services Terms were last updated on
17 +August 6, 2018.
18 +You can review prior versions at
19 +<https://github.com/npm/documentation/blob/main/content/policies/private-terms.mdx>.
20 +
21 +You may only access or use npm Paid Services by agreeing to the npm
22 +Open Source Terms as supplemented by these npm Paid Services Terms. If
23 +npm adds any additional functionality to npm Paid Services, you must
24 +agree to these npm Paid Services Terms to use those new features, too.
25 +You add these npm Paid Services Terms to your agreement with npm by
26 +using npm Paid Services with your account (your _Account_). These
27 +npm Paid Services Terms then become a part of the contract between you
28 +and npm, until you or npm disable npm Paid Services for your Account.
29 +
30 +## Payment Terms
31 +
32 +There is no charge for use of npm Open Source. If you use Paid Services,
33 +these payment terms apply. When enabling Paid Services, you must provide
34 +all the payment card details requested by the Website (your _Payment
35 +Details_). Those details must be for a valid payment card that you have
36 +the right to use (your _Payment Card_). You must keep your Payment
37 +Details up-to-date via the Website.
38 +
39 +You can disable Paid Services at any time via the Website. npm will not
40 +refund any payment you have already made for Paid Services when you
41 +disable Paid Services.
42 +
43 +Dollar amounts throughout this Agreement are amounts of United States
44 +Dollars. You must pay for Paid Services in United States Dollars.
45 +
46 +Dollar amounts throughout this Agreement do not include tax. You will
47 +pay any tax.
48 +
49 +## Use of npm Paid Services
50 +
51 +npm will provide the private package storage and delivery features and
52 +services described in the public documentation for npm Paid Services
53 +at <https://docs.npmjs.com/> (the _npm Paid Services
54 +Documentation_). npm grants you permission to use those features and
55 +services.
56 +
57 +npm will also provide the organization management and access control
58 +features described in the npm Paid Services Documentation, and grants
59 +you permission to use those features and services, for npm
60 +"organizations" to which your Account belongs.
61 +
62 +Permission to use npm Paid Services is not exclusive to you, and you
63 +may not transfer it to others. These npm Paid Services Terms do not
64 +give you permission to give others rights to use npm Paid Services.
65 +If you agree to a Payment Plan that gives you that right, you may do so
66 +only according to that Payment Plan.
67 +
68 +## Payment for npm Paid Services
69 +
70 +Both your permission to use npm Paid Services and npm's commitment to
71 +provide npm Paid Services are subject to these npm Paid Services
72 +Terms, the npm Open Source Terms, and payment for use of npm Paid
73 +Services by your Account under a _Payment Plan_. Payment plans include:
74 +
75 +1. the npm Solo Payment Plan at
76 + <https://docs.npmjs.com/policies/solo-plan>
77 +
78 +2. or the npm Orgs Payment Plan at
79 + <https://docs.npmjs.com/policies/orgs-plan>
80 +
81 +You may not use npm Paid Services unless you or someone else has
82 +agreed to a Payment Plan, enabled npm Paid Services for your Account
83 +under that Payment Plan, and made payment.
content/policies/security.mdx new
+286
@@ -0,0 +1,286 @@
1 +---
2 +title: npm Security Policy
3 +---
4 +
5 +Outlined in this document are the practices and policies that npm
6 +applies to help ensure that we release stable/secure software, and
7 +react appropriately to security threats when they arise.
8 +
9 +## Table of Contents
10 +
11 +1. [Reporting Security Problems to npm](#reporting-security-problems-to-npm)
12 +2. [Security Point of Contact](#security-point-of-contact)
13 +3. [Onboarding Developers](#onboarding-developers)
14 +4. [Separation of Duties and Authorization](#separation-of-duties-and-authorization)
15 +5. [Critical Updates And Security Notices](#critical-updates-and-security-notices)
16 +6. [Responding to Security Threats](#responding-to-security-threats-and-critical-updates)
17 +7. [Vulnerability Scanning](#vulnerability-scanning)
18 +8. [Password Policies](#password-policies)
19 +9. [Application Design Best Practices](#application-design-best-practices)
20 +10. [Development Process](#development-process)
21 +11. [AntiVirus Software](#antivirus-software)
22 +
23 +## Reporting Security Problems to npm
24 +
25 +If you need to report a security vulnerability. Please visit [https://npmjs.com/support](https://npmjs.com/support).
26 +If your issue is specific to your account, such as lost credentials or problems with two-factor authentication, contacting [our support team](https://npmjs.com/support) is more appropriate.
27 +
28 +We review all security reports on the next business day. Note that
29 +the npm staff is generally offline for most US holidays, but please do
30 +not delay your report! Our off-hours support staff can fix many
31 +issues, and will alert our security point of contact if needed.
32 +
33 +## Security Point of Contact
34 +
35 +Any security tickets opened using [https://npmjs.com/support](https://npmjs.com/support)
36 +will be escalated to the security point of contact, who will delegate incident response
37 +activities as appropriate. This is the best and fastest way to contact npm about any security-related matter.
38 +
39 +## Onboarding Developers
40 +
41 +All new technical hires are introduced to our security policy as part
42 +of the onboarding process.
43 +
44 +## Separation of Duties and Authorization
45 +
46 +* Developers are only given access to key npm services when it's required for their job.
47 +* IAM is used to limit the permissions on accounts, minimizing the damage that would be incurred if an account is compromised.
48 +
49 +## Critical Updates And Security Notices
50 +
51 +We learn about critical software updates and security threats from a
52 +variety of sources:
53 +
54 +* Ubuntu's security notices page: <https://usn.ubuntu.com/>
55 +* The Node.js mailing list.
56 +* [Security tickets](https://npmjs.com/support) sent to us.
57 +* and other media sources.
58 +
59 +### Ubuntu Automatic Security Updates
60 +
61 +Along with keeping an eye out for critical security updates, automatic
62 +security updates are enabled on all of our production servers allowing
63 +patches to be applied immediately without human intervention.
64 +
65 +<https://help.ubuntu.com/community/AutomaticSecurityUpdates>
66 +
67 +## Responding to Security Threats and Critical Updates
68 +
69 +When a security threat is identified, we have the following process in
70 +place:
71 +
72 +1. We have the slack channel `security-all`, which is used to
73 + prioritize and coordinate responses to security threats.
74 +2. Our [Security Point of Contact](#security-point-of-contact)
75 + oversees this discussion: managing the triage, responding to
76 + emails, and updating npm's status page.
77 +3. Based on the triage, work is allocated to developers to address the
78 + threat:
79 +
80 + * `P0`: Drop everything and fix!
81 + * `P1`: High severity, schedule work within 7 days.
82 + * `P2`: Medium severity, schedule work within 30 days.
83 + * `P3`: Low severity, fix within 180 days.
84 +
85 +## Vulnerability Scanning
86 +
87 +Along with reacting to security notifications as they happen, we
88 +proactively pen-test and audit software.
89 +
90 +### Internal Audits
91 +
92 +We have a dedicated security team who perform ongoing penetration testing, code auditing, and other forms of security oversight.
93 +
94 +While working on features at npm, all engineers coordinate security
95 +audits with the [Security Point of Contact](#security-point-of-contact).
96 +
97 +Documentation of our internal audits is available, and can be provided to customers when requested.
98 +
99 +### Automated Scanning
100 +
101 +The cloud hosting platforms that we use provide options for automated
102 +vulnerability scanning.
103 +
104 +* AWS: <https://aws.amazon.com/security/penetration-testing/>
105 +* Google Cloud: <https://cloud.google.com/security-scanner/>
106 +
107 +## Password Policies
108 +
109 +* Enable 2FA on all npm related accounts.
110 +* Passwords should be rolled every 90 days.
111 +* Passwords should contain alpha-numeric characters and symbols.
112 +* Passwords should be a minimum of 8 characters.
113 +* Any systems we build that accept a username and password should
114 + reject a user after repeated failed login attempts.
115 +
116 +### Don't Use Passwords
117 +
118 +We should opt for alternative authentication methods when possible:
119 +
120 +* Asymmetric keys for connecting to servers.
121 +* Delegated authentication (SAML, OAuth2, etc).
122 +* Opaque access tokens.
123 +
124 +### SSH Keys
125 +
126 +SSH keys should be rolled out selectively, providing developers access
127 +to only the servers that they require access to.
128 +
129 +## Application Design Best Practices
130 +
131 +In the next section of the document, we discuss the design
132 +methodologies that we use to build stable and secure software.
133 +
134 +### Logging Practices
135 +
136 +Logs are important for both debugging applications and detecting
137 +security breaches in our software.
138 +
139 +#### What We Log
140 +
141 +* We should track failed login attempts to servers:
142 + * Ubuntu provides this information in _/var/log/auth.log_
143 +* We should log the operations performed by users:
144 + * Ubuntu provides this information in _history_.
145 +* Applications should provide detailed operational logs in a
146 + [standardized format](https://github.com/ceejbot/common-log-string).
147 +
148 +#### Log format
149 +
150 +All applications should contain logging for `date`, `time`,
151 +`operation`, and a `unique request identifier`.
152 +
153 +We use
154 +[common-log-string](https://github.com/ceejbot/common-log-string)
155 +internally to standardize this:
156 +
157 +#### Backing Up Logs
158 +
159 +At least 90 days of logs should be kept for each service. On high
160 +traffic hosts this may require backing-up logs in cloud storage on a
161 +regular basis.
162 +
163 +#### Reviewing Logs
164 +
165 +On the servers that we manage for other companies, we should audit
166 +logs on a regular basis.
167 +
168 +
169 +#### Secrets in Logs
170 +
171 +Logs should not contain any sensitive user information, e.g.,
172 +passwords.
173 +
174 +The module [hide-secrets](https://www.npmjs.com/package/hide-secrets)
175 +is used to help with this.
176 +
177 +### Limiting Access to Operating System Files
178 +
179 +Micro-services should only have access to databases and files that
180 +they need access to.
181 +
182 +With our docker-based infrastructure (npm Enterprise) this is achieved by
183 +having containers only mount folders on the root host that they
184 +require access to.
185 +
186 +In our production environment, this is achieved by partitioning
187 +services across multiple hosts.
188 +
189 +### Security Groups
190 +
191 +Security groups are used to limit the network connectivity between hosts.
192 +
193 +When deploying a service, ask: "what other services does this
194 +actually need to connect to?"
195 +
196 +### Storage of Data
197 +
198 +Any sensitive user information should be encrypted at rest. Using
199 +[encrypted EBS
200 +drives](http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html),
201 +or an equivalent, is a great way to achieve this.
202 +
203 +### Inter-Service Communication
204 +
205 +Communication between services on the same host can be performed via
206 +HTTP.
207 +
208 +All inter-service communication between two hosts is performed using
209 +TLS.
210 +
211 +## Development Process
212 +
213 +npm has a well-defined, security-focused, development process:
214 +
215 +### Code Reviews
216 +
217 +No code goes into production unless it is reviewed by at least one
218 +other developer.
219 +
220 +The onus is on the reviewer to ask hard questions: "what are the
221 +ramifications of opening up port-X?", "why is this connection being
222 +made over HTTP instead of HTTPS?"
223 +
224 +### Deploying Updates
225 +
226 +* Any new code pushed to production is first thoroughly tested in a
227 + staging environment.
228 +* Mechanisms are in place for rolling back any changes that are pushed
229 + to production.
230 + * If a schema-change is involved, an inverse migration is first
231 + tested in staging (we want to be confident that we should role
232 + things back).
233 +
234 +### Unit Testing
235 +
236 +We love testing at npm:
237 +
238 +* During the code-review process, if you see logic that's complicated
239 + and lacks a test, politely ask the developer for a test.
240 +* It's particularly important that tests are added to logic that
241 + interacts with sensitive parts of the system: ACL logic, password
242 + validation, database access.
243 +* Tests should not contain user-data, make sure to anonymize email
244 + addresses, usernames, etc.
245 +* Test coverage is a great way to make sure all of the nooks and
246 + crannies of your codebase are tested. npm maintains two tools for
247 + test coverage internally [tap](https://github.com/isaacs/node-tap),
248 + and [nyc](https://github.com/bcoe/nyc).
249 +* Any new functionality should always come with a test to verify that
250 + it does what we think it does.
251 +* Any bug fix should always come with a test so that we don't have to
252 + encounter the same bug multiple times.
253 +
254 +### Design Cycle
255 +
256 +The design process, and management techniques vary from team to team
257 +at npm. Across the board, however, we strive to have continuous
258 +deployments. Releasing many small features as they become production
259 +ready.
260 +
261 +Security is taken into account during all phases of the software
262 +development life-cycle: unit tests think about potential threats; when
263 +testing on staging, we attempt to test potential exploits, etc.
264 +
265 +## AntiVirus Software
266 +
267 +On our managed Ubuntu hosts, we run the
268 +[ClamAV](https://help.ubuntu.com/community/ClamAV) AntiVirus software.
269 +
270 +### When A Virus Is Identified
271 +
272 +The infected server should be retired, and a new server should be
273 +provisioned from scratch.
274 +
275 +## Changes
276 +
277 +This is a living document and may be updated from time to time.
278 +Please refer to the [git history for this
279 +document](https://github.com/npm/documentation/blob/main/content/policies/security.mdx)
280 +to view the changes.
281 +
282 +## License
283 +
284 +This document may be reused under a [Creative Commons
285 +Attribution-ShareAlike
286 +License](https://creativecommons.org/licenses/by-sa/4.0/).
content/policies/solo-plan.mdx new
+29
@@ -0,0 +1,29 @@
1 +---
2 +title: Solo Payment Plan
3 +---
4 +
5 +This npm Solo Payment Plan (this _Payment Plan_) supplements
6 +the terms for npm Open Source offered by npm, Inc. (_npm_) at
7 +[https://docs.npmjs.com/policies/open-source-terms][open-source-terms] (_npm Open Source
8 +Terms_), as well as the terms for npm Paid Services (_npm Paid Services_)
9 +at [https://docs.npmjs.com/policies/private-terms][private-terms](_npm Paid
10 +Services Terms_). This Payment Plan governs payment for use of
11 +npm Solo by a single user account.
12 +
13 +This Payment Plan was last updated on
14 +August 6, 2018.
15 +You can review prior versions at
16 +<https://github.com/npm/documentation/blob/main/content/policies/solo-plan.mdx>.
17 +
18 +You will pay $7.00 via your Payment Card when you enable npm Solo
19 +for your Account by selecting this Payment Plan, and thereafter
20 +on the same day every month while this Payment Plan remains
21 +selected for your Account.
22 +
23 +Note that the npm Paid Services Terms require everyone using npm Paid
24 +Services to have an Account of their own, added under a Payment Plan.
25 +You may not allow anyone else to use npm Paid Services under this
26 +Payment Plan.
27 +
28 +[open-source-terms]: /policies/open-source-terms
29 +[private-terms]: /policies/private-terms
\ No newline at end of file
content/policies/terms.mdx new
+53
@@ -0,0 +1,53 @@
1 +---
2 +title: Terms and Licenses
3 +---
4 +npm, Inc. offers software and services under a few different licenses
5 +and terms of use.
6 +
7 +## Software from npm
8 +
9 +License terms and notices for the `npm` command-line program can
10 +be found in the LICENSE file of the project's source code at
11 +<https://www.github.com/npm/cli>.
12 +
13 +## Free to use npm services
14 +
15 +Free usage of <https://www.npmjs.com>, the npm public registry,
16 +and <https://npm.community>
17 +are covered by the npm Open Source Terms at <https://docs.npmjs.com/policies/open-source-terms>.
18 +These terms include several important policies, including:
19 +
20 +* What npm considers [acceptable package content][acceptable-use].
21 +
22 +* npm's [Code of Conduct][conduct], which includes our policy on harassment.
23 +
24 +* npm's [Privacy Policy][privacy], which limits use and sharing of information
25 +about you collected by npm Services.
26 +
27 +* npm's policy on [copyright][dmca] including how to report violations thereof.
28 +
29 +* npm's [Dispute Policy][disputes] which addresses how to resolve disputes
30 +over the control of a package name, user name, or organization name in the Public Registry. This includes
31 +our policy on users "squatting" on these names.
32 +
33 +* User of npm's trademarks is governed by our [Trademark Policy][trademark]. If you
34 +have concerns about your own trademark's use on npm please see our [Disputes Policy][disputes-trademark].
35 +
36 +## Paid npm services
37 +
38 +npm's paid products, including the npm Solo and Orgs plans, are
39 +covered by the npm Paid Services Terms at <https://docs.npmjs.com/policies/private-terms>.
40 +
41 +The [npm Solo Payment Plan][solo-plan]
42 +and the [npm Orgs Payment Plan][orgs-plan]
43 +govern payment for these services.
44 +
45 +[acceptable-use]: /policies/open-source-terms#acceptable-use
46 +[privacy]: /policies/privacy
47 +[dmca]: /policies/dmca
48 +[disputes]: /policies/disputes
49 +[trademark]: /policies/trademark
50 +[disputes-trademark]: /policies/disputes#trademarks
51 +[conduct]: /policies/conduct
52 +[orgs-plan]: /policies/orgs-plan
53 +[solo-plan]: /policies/solo-plan
\ No newline at end of file
content/policies/trademark.mdx new
+103
@@ -0,0 +1,103 @@
1 +---
2 +title: npm Trademark Policy
3 +---
4 +
5 +This policy describes npm trademarks and how you may use them.
6 +For information on what to do if someone infringes a trademark of
7 +_yours_ with a confusing package name, see the [Dispute Resolution Policy][disputes].
8 +
9 +## What is npm?
10 +
11 +The npm project contains two main parts:
12 +
13 +1. The npm client. It is a command line tool to install and publish packages.
14 +2. The npm registry service. npm, Inc. runs the registry as a free (as in beer) public service for anyone
15 +wanting to publish an open source package and for anyone to install an open source package.
16 +
17 +## Why npm, Inc. has a trademark policy
18 +
19 +"npm" and the npm logos are trademarks owned by npm, Inc. We have developed this trademark usage policy to make it clear how other businesses and projects can (and cannot) use the npm name and logos.
20 +
21 +## General rules
22 +
23 +* When referring to the npm software in body text, the first usage should be followed by a generic term such as "package manager," "services" or "client" to provide context.
24 +* "npm" should never be used or explained as an acronym.
25 +* When referring to the npm public registry, please follow npm with the word "registry" or the phrase "public registry".
26 +* When referring to a private registry for npm packages, please describe it as "private registry for npm packages" or a "proxy of the npm registry".
27 +* References to the owner of the npm client software and the operator of the npm public registry should be to "npm, Inc."
28 +* Any materials referring to npm should include the following notice in the footer or wherever you may have your own trademark notice: "npm is a registered trademark of npm, Inc."
29 +
30 +## Nominative use - No need to type ™ on Twitter&reg;
31 +
32 +"Nominative" or "referential" use means to refer to something or someone else by their trademark. So it's perfectly OK to use "npm" to refer to npm, Inc., the npm client, npm code, and the npm public registry. A referential use is generally going to be in a sentence or sentence fragment, like "first install the npm client," or in a book or article title. The use should not be attention-getting or potentially misperceived as suggesting "npm" is your own name, project, product or services.
33 +
34 +It is not a referential use to incorporate the letters "npm" or any of the npm logos in the name or logo for your own company or its projects, products, services or social media handles.
35 +
36 +If you need to use "npm" to indicate compatibility, you should use "npm" after your own product or service name and an accurate preposition:
37 +
38 +* Pink Unicorn Consulting Ltd. services <strong>for</strong> npm
39 +* Purple Unicorn Inc. private registry server <strong>compatible with</strong> the npm client
40 +* Kappa, a hirearchical proxy <strong>of</strong> the npm registry
41 +
42 +You need to ask for permission for any uses not described. When in doubt about your use of the npm name or logo, please contact [npm, Inc.](https://www.npmjs.com/contact) for clarification.
43 +
44 +## Requesting permission
45 +
46 +We like to make it easy for anyone to use the npm name or logo for community-oriented efforts that help spread and improve npm. We are therefore likely to grant permission to use the npm name and logo in the following ways:
47 +
48 +* For projects where:
49 + * The primary purpose of your project is to promote the spread and
50 + improvement of the npm client software or the npm registry service.
51 + * Your project is non-commercial in nature (it can make money to cover
52 + its costs or contribute to non-profit entities, but it cannot be run
53 + as a for-profit project or business).
54 + * Your project neither promotes nor is associated with entities that
55 + currently fail to comply with the Artistic License 2.0 under which
56 + npm is distributed, or which are in violation of this trademark
57 + policy.
58 +
59 +* For a user group name where:
60 + * The main focus of the group is the software.
61 + * Any software or services the group provides are without cost.
62 + * The group does not make a profit.
63 + * Any charge to attend meetings are to cover the cost of the venue, food and drink only.
64 +
65 +Any other requests are not likely to be granted licenses, but feel free to [ask](https://www.npmjs.com/contact).
66 +
67 +## The npm Logos
68 +
69 +Our npm Logos are very recognizable and deserves special treatment. The
70 +npm Logos signify us, or a special relationship with us, and you
71 +may use them only with our permission. Since the goal is to avoid
72 +confusion about you being us, or your relationship with us, context
73 +counts. We will [consider requests](https://www.npmjs.com/contact) on a case-by-case basis.
74 +
75 +## The npm Wombat Mascot
76 +
77 +Like the npm Logo, the npm Wombat graphic is a very recognizable
78 +part of the npm brand, and signifies a special relationship with
79 +the npm project, service, or company. It should never be used except
80 +with explicit written permission. We will [consider requests](https://www.npmjs.com/contact) on a
81 +case-by-case basis.
82 +
83 +Please be advised that the Wombat and the logos generally may
84 +**not** be used to refer to the project, service, or company in a
85 +nominative sense, as any usage will almost always imply a special
86 +relationship with npm.
87 +
88 +## Changes
89 +
90 +This is a living document and may be updated from time to time.
91 +Please refer to the [git history for this
92 +document](https://github.com/npm/documentation/blob/main/content/policies/trademark.mdx)
93 +to view the changes.
94 +
95 +## License
96 +
97 +Copyright &copy; npm, Inc.
98 +
99 +This document may be reused under a [Creative Commons
100 +Attribution-ShareAlike
101 +License](https://creativecommons.org/licenses/by-sa/4.0/).
102 +
103 +[disputes]: /policies/disputes
\ No newline at end of file
content/policies/unpublish.mdx new
+78
@@ -0,0 +1,78 @@
1 +---
2 +title: npm Unpublish Policy
3 +---
4 +
5 +This document describes your options when looking to unpublish a package published to the public registry.
6 +
7 +Registry data is immutable, meaning once published, a package cannot change. We do this for reasons of security and stability of the users who depend on those packages. So if you've ever published a package called "bob" at version 1.1.0, no other package can ever be published with that name at that version. This is true even if that package is unpublished.
8 +
9 +However, because accidents happen, we allow you to unpublish packages in the situations described below. Otherwise, you can always deprecate a package.
10 +
11 +## Packages published less than 72 hours ago
12 +
13 +For newly created packages, as long as no other packages in the npm Public Registry depend on your package, you can unpublish anytime within the first 72 hours after publishing.
14 +
15 +## Packages published more than 72 hours ago
16 +
17 +Regardless of how long ago a package was published, you can unpublish a package that:
18 +
19 +- no other packages in the npm Public Registry depend on
20 +- had less than 300 downloads over the last week
21 +- has a single owner/maintainer
22 +
23 +## How to unpublish
24 +
25 +To unpublish a single package version, run `npm unpublish <package_name>@<version>`.
26 +
27 +If all the versions of a package can be unpublished, you can unpublish all versions at once by running `npm unpublish <package_name> --force`.
28 +
29 +## Considerations:
30 +
31 +- Once `package@version` has been used, you can never use it again. You must publish a new version even if you unpublished the old one.
32 +- Once you have unpublished a package, you will not be able to undo the unpublish.
33 +- If you entirely unpublish all versions of a package, you may not publish any new versions of that package until 24 hours have passed.
34 +
35 +## What to do if your package does not meet the unpublish criteria?
36 +
37 +If your package does not meet the unpublish policy criteria, we recommend [deprecating](https://docs.npmjs.com/cli/deprecate) the package. This allows the package to be downloaded but publishes a clear warning message (that you get to write) every time the package is downloaded, and on the package's npmjs.com page. Users will know that you do not recommend they use the package, but if they are depending on it their builds will not break. We consider this a good compromise between reliability and author control.
38 +
39 +This can be achieved by using one of the following from your command line:
40 +
41 +- `npm deprecate <package> "<message>"` to deprecate the entire package
42 +- `npm deprecate <package>@<version> "<message>"` to deprecate a specific version
43 +
44 +If the entire package is deprecated, the package name will be dropped from our search results.
45 +
46 +Once deprecated, if you would also like for the package to be removed from your user profile, it can be [transferred](https://docs.npmjs.com/cli/owner) to our [@npm](https://www.npmjs.com/~npm) account. This can be achieved by using the following from your command line:
47 +
48 +- `npm owner add npm <package>`
49 +- `npm owner rm <your_username> <package>`
50 +
51 +
52 +## More on our unpublish policy
53 +
54 +This document is additive to the [unpublish procedures](https://docs.npmjs.com/unpublishing-packages-from-the-registry), the CLI commands [unpublish documentation](https://docs.npmjs.com/cli/unpublish) and the ["Changes to npm Unpublish Policy - January 2020"](https://blog.npmjs.org/post/190553543620/changes-to-npm-unpublish-policy-january-2020) blog post.
55 +
56 +## Issues?
57 +
58 +If for some reason your package meets the unpublish policy criteria but the unpublish command fails, or if you need assistance with the deprecate process, please [reach out to our support team](https://npmjs.com/support) where we'll be happy to assist.
59 +
60 +If you believe a package violates npm's terms or policies, such as our terms of use, [reach out to our support team](https://www.npmjs.com/support). If a package infringes your copyright, [refer to npm's DMCA takedown policy][dmca]. If you believe a package violates your privacy rights, [contact our privacy team][contact] as soon as possible.
61 +
62 +## Changes
63 +
64 +This is a living document and may be updated from time to time.
65 +Please refer to the [git history for this
66 +document](https://github.com/npm/documentation/blob/main/content/policies/unpublish.mdx)
67 +to view the changes.
68 +
69 +## License
70 +
71 +Copyright (C) npm, Inc., All rights reserved
72 +
73 +This document may be reused under a [Creative Commons
74 +Attribution-ShareAlike
75 +License](https://creativecommons.org/licenses/by-sa/4.0/).
76 +
77 +[dmca]: /policies/dmca
78 +[contact]: /policies/privacy#contact
\ No newline at end of file
gatsby-node.js
+3 -2
@@ -9,8 +9,9 @@ exports.onCreateNode = ({node, actions, getNode}) => {
9 return;
10 }
11
12 - // directory index paths are unchanged
13 - if (file.name === 'index') {
12 + // directory index paths and policy are unchanged
13 + if (file.name === 'index' ||
14 + file.relativeDirectory.match('^policies(\/.*)?$')) {
15 return;
16 }
17
src/gatsby-theme-doctornpm/nav.yml
+27
@@ -294,6 +294,33 @@
294 children:
295 - title: Sunsetting npm Enterprise
296 url: /sunsetting-npm-enterprise
297 +- title: Policies
298 + url: /policies
299 + children:
300 + - title: Terms of Use
301 + url: /policies/terms
302 + - title: Code of Conduct
303 + url: /policies/conduct
304 + - title: Package Name Disputes
305 + url: /policies/disputes
306 + - title: npm License
307 + url: /policies/npm-license
308 + - title: Privacy Policy
309 + url: /policies/privacy
310 + - title: Unpublish Policy
311 + url: /policies/unpublish
312 + - title: Receiving Abuse Reports
313 + url: /policies/receiving-reports
314 + - title: Copyright and DMCA Policy
315 + url: /policies/dmca
316 + - title: Trademark Policy
317 + url: /policies/trademark
318 + - title: Security
319 + url: /policies/security
320 + - title: Replication and web crawler policy
321 + url: /policies/crawlers
322 + - title: Our official list of domains
323 + url: /policies/domains
324 - title: npm CLI
325 shortName: CLI
326 url: /cli
src/nav-base.yml
+28
@@ -295,3 +295,31 @@
295 children:
296 - title: Sunsetting npm Enterprise
297 url: /sunsetting-npm-enterprise
298 +
299 +- title: Policies
300 + url: /policies
301 + children:
302 + - title: Terms of Use
303 + url: /policies/terms
304 + - title: Code of Conduct
305 + url: /policies/conduct
306 + - title: Package Name Disputes
307 + url: /policies/disputes
308 + - title: npm License
309 + url: /policies/npm-license
310 + - title: Privacy Policy
311 + url: /policies/privacy
312 + - title: Unpublish Policy
313 + url: /policies/unpublish
314 + - title: Receiving Abuse Reports
315 + url: /policies/receiving-reports
316 + - title: Copyright and DMCA Policy
317 + url: /policies/dmca
318 + - title: Trademark Policy
319 + url: /policies/trademark
320 + - title: Security
321 + url: /policies/security
322 + - title: Replication and web crawler policy
323 + url: /policies/crawlers
324 + - title: Our official list of domains
325 + url: /policies/domains