diff --git a/README/setup_swiftpm_skipautointegrate.png b/.github/assets/setup_swiftpm_skipautointegrate.png similarity index 100% rename from README/setup_swiftpm_skipautointegrate.png rename to .github/assets/setup_swiftpm_skipautointegrate.png diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..f6bdbc9 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,132 @@ +# Contributor Covenant Code of Conduct + +## Our Pledge + +We as members, contributors, and leaders pledge to make participation in our +community a harassment-free experience for everyone, regardless of age, body +size, visible or invisible disability, ethnicity, sex characteristics, gender +identity and expression, level of experience, education, socio-economic status, +nationality, personal appearance, race, caste, color, religion, or sexual +identity and orientation. + +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards + +Examples of behavior that contributes to a positive environment for our +community include: + +- Demonstrating empathy and kindness toward other people +- Being respectful of differing opinions, viewpoints, and experiences +- Giving and gracefully accepting constructive feedback +- Accepting responsibility and apologizing to those affected by our mistakes, + and learning from the experience +- Focusing on what is best not just for us as individuals, but for the overall + community + +Examples of unacceptable behavior include: + +- The use of sexualized language or imagery, and sexual attention or advances of + any kind +- Trolling, insulting or derogatory comments, and personal or political attacks +- Public or private harassment +- Publishing others' private information, such as a physical or email address, + without their explicit permission +- Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Enforcement Responsibilities + +Community leaders are responsible for clarifying and enforcing our standards of +acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, offensive, +or harmful. + +Community leaders have the right and responsibility to remove, edit, or reject +comments, commits, code, wiki edits, issues, and other contributions that are +not aligned to this Code of Conduct, and will communicate reasons for moderation +decisions when appropriate. + +## Scope + +This Code of Conduct applies within all community spaces, and also applies when +an individual is officially representing the community in public spaces. +Examples of representing our community include using an official e-mail address, +posting via an official social media account, or acting as an appointed +representative at an online or offline event. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the community leaders responsible for enforcement listed on the +[project's `README`](https://github.com/sumup-oss/circuit-ui#maintainers). +All complaints will be reviewed and investigated promptly and fairly. + +All community leaders are obligated to respect the privacy and security of the +reporter of any incident. + +## Enforcement Guidelines + +Community leaders will follow these Community Impact Guidelines in determining +the consequences for any action they deem in violation of this Code of Conduct: + +### 1. Correction + +**Community Impact**: Use of inappropriate language or other behavior deemed +unprofessional or unwelcome in the community. + +**Consequence**: A private, written warning from community leaders, providing +clarity around the nature of the violation and an explanation of why the +behavior was inappropriate. A public apology may be requested. + +### 2. Warning + +**Community Impact**: A violation through a single incident or series of +actions. + +**Consequence**: A warning with consequences for continued behavior. No +interaction with the people involved, including unsolicited interaction with +those enforcing the Code of Conduct, for a specified period of time. This +includes avoiding interactions in community spaces as well as external channels +like social media. Violating these terms may lead to a temporary or permanent +ban. + +### 3. Temporary Ban + +**Community Impact**: A serious violation of community standards, including +sustained inappropriate behavior. + +**Consequence**: A temporary ban from any sort of interaction or public +communication with the community for a specified period of time. No public or +private interaction with the people involved, including unsolicited interaction +with those enforcing the Code of Conduct, is allowed during this period. +Violating these terms may lead to a permanent ban. + +### 4. Permanent Ban + +**Community Impact**: Demonstrating a pattern of violation of community +standards, including sustained inappropriate behavior, harassment of an +individual, or aggression toward or disparagement of classes of individuals. + +**Consequence**: A permanent ban from any sort of public interaction within the +community. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], +version 2.1, available at +[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1]. + +Community Impact Guidelines were inspired by +[Mozilla's code of conduct enforcement ladder][mozilla coc]. + +For answers to common questions about this code of conduct, see the FAQ at +[https://www.contributor-covenant.org/faq][faq]. Translations are available at +[https://www.contributor-covenant.org/translations][translations]. + +[homepage]: https://www.contributor-covenant.org +[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html +[mozilla coc]: https://github.com/mozilla/diversity +[faq]: https://www.contributor-covenant.org/faq +[translations]: https://www.contributor-covenant.org/translations diff --git a/LICENSE b/LICENSE index 5b30a57..f9bd2d0 100644 --- a/LICENSE +++ b/LICENSE @@ -1,24 +1,201 @@ -SumUp SDK License + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ -SumUp Payments Limited, UK company number 07836562, (“SumUp”), is providing or making available the software code (the “Software”) and all other documents, specifications and other items (the “Documentation”) for use under the terms of this software development kit license agreement (the “Agreement”). By downloading or otherwise gaining access to the Software and Documentation you agree to be bound by this Agreement. SumUp may at any time subject to SumUp’s notice to you in writing or by e-mail renew, modify or amend this Agreement from time to time. SumUp will then make such new version of this Agreement available to you via email or by other means of communication. If you continue to use the Software and Documentation, you are deemed to have accepted such renewal, modification or amendment. If you agree to this Agreement on behalf of your employer or another legal entity, you warrant that you have the right to enter into this Agreement on behalf of such other party. +TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION -1. License grant, etc. -Subject to the terms of this Agreement, SumUp hereby grants to you a non-exclusive, non-transferable, non sub-licensable, worldwide, royalty free license to use the Software and Documentation to develop your mobile applications (i.e. one or more software programs developed by you under your own trademark or brand and which will be provided to end-user’s smart phones or tablets from market places such as Apple App Store), in which the Software and Documentation will be incorporated and which will provide access to SumUp’s services. SumUp may without prior notice to you change the form and nature of the Software and Documentation that SumUp provides which may lead to that future versions of the Software and Documentation may be incompatible with mobile applications developed on previous versions of the Software and Documentation. Furthermore, SumUp may stop (permanently or temporarily) providing the Software and Documentation (or any features within the Software and Documentation) to you or to users generally, at SumUp’s sole discretion without prior notice to you. SumUp may make updates of the Software and Documentation at any time, but shall have no obligation what so ever to provide any updates of the Software and Documentation to you. Except to the extent expressly permitted by any applicable third party license, you may not copy (except for backup purposes), modify, adapt, redistribute, decompile, reverse engineer, disassemble, or create derivative works of the Software or Documentation or any part of the Software or Documentation or any services provided by the Software or Documentation. You may not remove, obscure, or alter any proprietary rights notices (including copyright and trademark notices) that may be affixed to or contained within the Software or Documentation. You must comply with all third party licenses in order to use the third party software contained in the Software. No title to the intellectual property in the Software or Documentation is transferred to you under the terms of this Agreement. You do not acquire any rights to the Software or Documentation except as expressly set forth in this Agreement. You agree to use the Software and Documentation for development of your mobile applications only and for purposes that are permitted by (a) this Agreement and (b) any applicable law, regulation or generally accepted practices or guidelines in the relevant jurisdictions (including any laws regarding the export of data or software (including encryption software) to and from the European Union, the United States or other relevant countries). You agree that you will not engage in any activity with the Software or Documentation, including the development or distribution of applications that interferes with, disrupts, damages, or accesses in an unauthorized manner the servers, networks, or other properties or services of SumUp or any third party including, but not limited to any mobile communications carrier. All ownership and intellectual property rights in the Software and Documentation and any copies and derivative works thereof (regardless of form or media in or on which the original or other copies may exist), including but not limited to patents, design rights, copyrights, trade marks, trade-secrets and proprietary know-how, shall be owned by and vested in SumUp, or SumUp’s licensors, and nothing in this Agreement shall constitute or be interpreted as a transfer of such rights from SumUp to you. You are solely entitled to the limited license to the Software or Documentation specifically granted under this Agreement. You acknowledge that the structure and code of the Software are valuable trade secrets of SumUp which shall remain the sole property of SumUp. At present, the Software and Documentation is provided by SumUp to you free of charge. However, SumUp has the right to at any time, if deemed necessary by SumUp, charge you a license fee for the Software and Documentation. If SumUp decides at its own discretion to charge you for the access to and use of the Software and Documentation, SumUp will provide you with an invoice stating inter alia the amount and the bank account number to which you shall transfer such license fee. +1. Definitions. -2. Disclaimer. -SumUp licenses the Software and Documentation to you only on an "as is" basis without warranties or conditions of any kind, either express or implied, including without limitation any warranties or conditions of title, non-infringement, merchantability or fitness for a particular purpose. SumUp makes no warranty that the Software and Documentation will be error-free. Each user of the Software or Documentation is solely responsible for determining the appropriateness of using the Software and Documentation and assumes all risks associated with its exercise of rights under this Agreement, including but not limited to the risks and costs of program errors, compliance with applicable laws, damage to or loss of data, programs, or equipment, and unavailability or interruption of operations. Use of the Software and Documentation is made with the understanding that SumUp will not provide you with any technical or customer support or maintenance. + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. -3. Limitation of liability. -Neither SumUp nor its subsidiaries, affiliates, officers, agents or other partners, and employees shall be liable for loss or damage arising out of this Agreement or from the use of the Software or Documentation. In no event will SumUp or its subsidiaries, affiliates, officers, agents or other partners, and employees be liable to you or any third party for any direct, indirect, consequential, incidental, or special damages including lost profits, lost savings, costs, fees, or expenses of any kind arising out of any provision of this agreement or the use or the inability to use the Software or Documentation, however caused and under any theory of liability, whether in contract, strict liability or tort including negligence or otherwise), even if advised of the possibility of such damages. SumUp's aggregate liability and that of its suppliers under or in connection with this Agreement shall be limited to the amount paid by you for the Software and Documentation. + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. -4. Indemnity. -You shall indemnify and hold SumUp and its subsidiaries, affiliates, officers, agents or other partners, and employees, harmless from any claim or demand (including without limitation attorneys’ fees) made by any third party due to or arising out of your use of the Software and Documentation, your breach of this Agreement or your violation of any rights of another person or entity. You agree that you are solely responsible for (and that SumUp has no responsibility to you or to any third party for) any breach of your obligations under this Agreement, any applicable third party contract or any applicable law or regulation, and for the consequences (including any loss or damage which SumUp or any third party may suffer) of any such breach. You may not enter into any settlement or like agreement with any third party that affects SumUp’s right or binds SumUp in any way, without the prior written consent of SumUp. + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. -5. Confidentiality. -You are aware that the Software and Documentation constitute trade secrets and contains confidential information (”Confidential Information”). You agree to protect all Confidential Information using at least the same degree of care that you use to protect your own confidential information, however not less than a reasonable degree of care. You agree to use Confidential Information solely for the purpose of exercising your rights and performing your obligations under this Agreement and agree not to use the Confidential Information for any other purpose, without SumUp’s prior written consent. Furthermore, you agree not to make the Software and Documentation available to a third party without SumUp’s prior written consent and to with take all reasonable measures to ensure that any Confidential Information is not disclosed or otherwise furnished, directly or indirectly, to any third party. Your confidentiality obligation hereunder shall not apply to Confidential Information which You can evidence: (i) is already known by you when received; (ii) is or has becomes public knowledge other than through a breach of this Agreement; (iii) is received from a third party who lawfully acquired it and who is under no obligation restricting its disclosure; or (iv) is to be made publicly available due to a court order, a decision by a public body or as otherwise required by mandatory law. You agree to impose on your employees and consultants, if applicable, in an appropriate manner, the obligations regarding the use of the Software and Documentation set forth in this Agreement and the obligation of confidentiality set out hereunder. You shall be liable in relation to SumUp for your employees’ and consultants’ actions and for their observance of this Agreement and the obligation of confidentiality set out hereunder. Your obligations of confidentiality hereunder shall be valid during the term of this Agreement and continue for a period thereafter of five (5) years after expiration or termination of the Agreement, regardless of the reason therefore. + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. -6. Term. -This Agreement shall commence as set forth above, and continue to be in full force until terminated. SumUp has the right to terminate the Agreement if you fail to comply with any term of the Agreement. Furthermore, either party may terminate this Agreement for its convenience effective thirty (30) days after providing the other party written notice of termination. Upon termination of this Agreement for whatever reason, you agree to immediately cease all use of the Software and Documentation and to erase and destroy all copies of the Software and Documentation in your possession or control. SumUp will not have any liability to compensate you for any damages which you may suffer due to SumUp’s termination of this Agreement. + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. -7. Governing law and dispute resolution. -This Agreement shall be governed by and construed in accordance with English substantive law. Any dispute, controversy or claim arising out of or in connection with this Agreement, or the breach, termination or invalidity thereof, shall be finally settled by arbitration administered by the Courts of England. + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + +2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + +3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + +4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + +5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + +6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + +7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + +8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + +9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + +END OF TERMS AND CONDITIONS + +APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + +Copyright 2019 SumUp Ltd + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. diff --git a/README.md b/README.md index 0a603f5..7a8b091 100644 --- a/README.md +++ b/README.md @@ -140,7 +140,7 @@ Requirement: Xcode 12 beta 6 (swift-tools-version:5.3) 1. Add the package dependency to the repository `https://github.com/sumup/sumup-ios-sdk` (*File > Swift Packages > Add Package Dependency...*) with the version `Up to Next Major: 4.0.0` 2. Leave the checkbox unchecked for the SumUpSDK at the integration popup (*Add Package to ...:*) -![Swift PM - do not auto-integrate SDK](README/setup_swiftpm_skipautointegrate.png) +![Swift PM - do not auto-integrate SDK](.github/assets/setup_swiftpm_skipautointegrate.png) 3. From the Project Navigator, drag and drop the `SumUpSDK/Referenced Binaries/SumUpSDK.xcframework` to your Xcode project's "Frameworks, Libraries, and Embedded Content" on the General settings tab. 4. Make sure the [required Info.plist keys](#privacy-info-plist-keys) are present. diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..d9e807b --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,21 @@ +# Security Policy + +The security of _SumUp mPOS SDK - iOS_ is of paramount importance to us, and we genuinely appreciate the community's efforts to identify and report vulnerabilities. + +## Supported Versions + +We recommend users stay updated with the latest version of our project for optimal stability and security. + +## Reporting a Vulnerability + +Please do not open GitHub issues or pull requests - this makes the vulnerability immediately visible to everyone, including malicious actors. Security issues in this open-source project can be safely reported via the private SumUp bug bounty program. + +To get an invite to our Hackerone private bug bounty program reach out to us via bugbounty at sumup com. + +The SumUp security team will triage your report and determine whether or not is it eligible for a bounty under our program. + +## General Guidelines + +- **Prioritize Confidentiality:** We urge you not to disclose the vulnerability publicly until it's been addressed, ensuring the broader community isn't inadvertently put at risk. +- **Ethical Practices:** Engage in responsible and ethical behavior. Refrain from actions that compromise user privacy, system integrity, or availability. +- **When in Doubt, Reach Out:** If you're uncertain about the significance of a potential security issue, it's always better to err on the side of caution and notify us.