move CODE_OF_CONDUCT and SECURITY to markdown

Islon Scherer 2024-07-22
## Code of Conduct
### Our Pledge
In the interest of fostering an open and welcoming environment, we as
contributors and maintainers pledge to making participation in our
education, socio-economic status, nationality, personal appearance,
race, religion, or sexual identity and orientation.
### Our Standards
Examples of behavior that contributes to creating a positive environment
Examples of unacceptable behavior by participants include:
attention or advances
attention or advances
* Trolling, insulting/derogatory comments, and personal or political
* Public or private harassment
* Publishing others private information, such as a physical or
electronic address, without explicit permission
electronic address, without explicit permission
* Other conduct which could reasonably be considered inappropriate in a
professional setting
professional setting
### Our Responsibilities
Project maintainers are responsible for clarifying the standards of
acceptable behavior and are expected to take appropriate and fair
temporarily or permanently any contributor for other behaviors that they
deem inappropriate, threatening, offensive, or harmful.
### Scope
This Code of Conduct applies within all project spaces, and it also
applies when an individual is representing the project or its community
@ -55,7 +55,7 @@ official social media account, or acting as an appointed representative
at an online or offline event. Representation of a project may be
further defined and clarified by project maintainers.
### Enforcement
Instances of abusive, harassing, or otherwise unacceptable behavior may
be reported by contacting the open source team at
good faith may face temporary or permanent repercussions as determined
by other members of the projects leadership.
### Attribution
available at
[Contributor Covenant](, version 1.4,
available at

# Security
For the protection of our community, the Pkl team does not disclose, discuss, or confirm security issues until our investigation is complete and any necessary updates are generally available.
## Reporting a security vulnerability
If you have discovered a security vulnerability within the Pkl VSCode project, please report it to us.
We welcome reports from everyone, including security researchers, developers, and users.
Security vulnerabilities may be reported on the [Report a vulnerability]( form.
When submitting a vulnerability, select "Apple Devices and Software" as the affected platform, and "Open Source" as the affected area.
For more information, see