Rethinking codes of conduct

Did you know that the Python Software Foundation Code of Conduct is turning 10 years old in 2023? It was voted in as they felt they were “unbalanced and not seeing the true spectrum of the greater community”. And thought that with time they could “advance towards a more diverse representation.”[1]

Why is that a big thing? Codes of conduct are an important part of any community, outlining the values of the community. They establish clear guidelines for acceptable behavior and help to create a safe and inclusive environment in the community. This can prevent discrimination and promote equal opportunities for all members.

In this talk, we will explore the role of code of conduct in communities, it’s history in the PSF, and discuss strategies for rethinking what it means to have and enforce a Code of Conduct. We will look at the existing challenges that the Python communities face when implementing codes of conduct and talk about possible solutions. How does it look like when it works well and when it doesn’t?

As an essential part of any open source project, reflecting on these guidelines can help to ensure that the projects are successful and sustainable in the long term. Thinking back to Python, which also turns 20 in 2023: “Python got to where it is by being open, and it’ll continue to prosper by remaining open”. It’s important we continue this mission, after all, one of the things many people love about Python is the community.

[1] https://pyfound.blogspot.com/2013/06/announcing-code-of-conduct-for-use-by.html

This session took place in track Community, Diversity, Career, Life and everything else and was classified suitable for novice domain by the speaker.

Transcript (auto)

Auto-generated from the recording utilizing Open-Source AI. Speaker labels (Speaker 1, Speaker 2) reflect diarization, not identity. Timestamps refer to the recording.

Speaker 1 [00:03]

Welcome to the last talk of the stage today. So today we're going to talk about rethinking codes of conduct. A little bit of disclaimer about this talk. This is not a coding talk, so it's not about... There's not so much scientific information that I can vouch for. Mostly it's about opinions and... My opinions. And other people's opinions. So don't, like, if you disagree, that's totally fine. Okay, so let's, yeah, so this is an old painting that I found. Okay, so, oops, no, I did, okay. So, yeah, about me. So my pronouns are she, her. You can reach me at hello at teresayovch.com. This is the picture of a meetup we had with the diversity and inclusion work group with the Python Software Foundation that I'm part of. I am head of data science at Noe Fisher. We do data science boot camps and I'm also offering leadership coaching. So if you need an inclusive leadership coaching, I'm organiser of the PyLadies Hamburg. I am on the board of the Python Software Verband, which is running this conference, and I'm also part of the Code of Conduct work group and the Diversity and Inclusion work groups of the Python Software Foundation, and because I have a lot of free time, I am also part of the DISC committee, which is the Diversity and Inclusion in Scientific Computing with name focus group. And I also do artsy stuff and knit under the tupyup label which don't ask what it means. So, a lot of hats. Let's say I don't get bored, and I wasn't planning on giving this talk here today, but some speakers decided they couldn't make it anymore, so here I am. So, first question, who here is contributing to open source by this definition? You're contributing, you're writing bug reports, you're maintainers, okay, cool, okay. What about the invisible work? Who here is contributing to open source according to this additional definition? Working in education, educating other people, supporting people, governance, spreading the work, organising conferences, volunteering at conferences, already we see that all the people with the green T-shirt, they obviously contribute to open source because you have volunteer or organizer swag. So, yeah. Some people say that the glue of all this open source working out and surviving is the community behind it. So why do we like Python? This is a 2017 quote from Brett Cannon. I came here for the language, but I stayed for the the community, and this was a picture taken at PyCon 2017, and people already posted that on T-shirts. A little bit of a short history of Python, according to me, of course, from a German perspective, so there's a lot of stuff happening in Python, so I'm not going to go there, but in case you didn't know, in 1991, Guido von Rossum released the first Python version. I don't know if it was Python 1 or something. Anyway. Then I think in 2001 the Python Software Foundation was formed, so it's quite late. Then in 2003 we had the first PyCon US, which is happening, started now, so they are having a 20-year anniversary. In 2004 the Python Software Fairbairn, the one that is financing and running this conference, was formed and it had a funny name that nobody remembers. I mean, some people remember, but I don't remember, so I think somebody nods in the back so he knows. I also just found out the name this week because, they had to rename it because it was a funny name. In 2011, we had the first PyCon DE in Leipzig, I think. So, quite a long time ago. Anybody here was there? Wow, okay, that's cool. So, yeah, then what happened? In 2012, NumFocus gets created. So PyCon D is older than NumFocus. And in 2013, the PSF announces its first code of conduct. So quite a lot of stuff happened before code of conduct came on, you know, in play. In 2018, around 2018, SageSharp author technologies updated the Python software foundation code of conduct. Why I'm mentioning this is because at the moment the Python Software Foundation code of conduct is one of the better written codes of conduct out there. And I will talk today a little bit about why that matters. So why do we need a code of conduct? So why did Python Software Foundation need a code of conduct? So this is a link, you can scan it, it's a blog on the PSF site. it was voted as they felt, so 10 years ago, so the PSF code of conduct is going to be 10 years old today, this year. It was voted because they felt they were unbalanced and not seeing the true spectrum of the greater community and thought that with time, they could advance towards a more diverse representation. So this is what we wanted 10 years ago. And let's do a small exercise now, because some of us were like, why should we care about codes of conduct, right? Everything is fine, nothing happened today, everything was well, usually nothing bad happens, but let's think of situations. So who here can think of a situation you had a conflict or tension with another person? You know, like, it can be at work, it can be in the Python community, in another Python community, there's a lot of Python, in general, yeah? Think of a situation where someone wrote or spoke using language that made you feel unwelcome. Yeah? Think about a situation where you felt you were stereotyped based on your perceived demographics. Yeah. Okay, this is a hard one. You were stalked or harassed. Yeah. So, question number one to think about it. Did you tell someone? Yeah? Some people said, did you report it? Some people reported, yeah? Was it easy to talk about it? No. Okay. Let's do the other side of the coin. Think of a situation where someone had a conflict or tension with you. Yeah, it happens to the best of us. I mean, we can be on both sides of the coin. You wrote or spoke using a language that made someone feel unwelcome. Yeah. You stereotype based on perceived demographics. Okay, I'm not going to ask about stalking. Please don't. Yeah, so let's, yeah. So, but the questions here come on the other side. Were you able to receive feedback elegantly? Yeah, it's uncomfortable, right? It's like someone comes and tells you, hey, you are an asshole, and you're like, what? I'm never an asshole. Did you find it easy to understand what you did wrong? Because in our inner mirror, our mirror shows us as perfect people, and then comes someone that says you're not perfect, and it shatters our universe. So we may, at any given point in time, be on any side of the coin. It's just because we are all different, and it's really hard to, you know, you don't grow up in other people's shoes and they don't grow up in your shoes and it takes a lifetime of learning how to, you know, identify other people's shoes. And why does it matter? Because who is contributing to open source? So this is a map, like the geography of open source from, I think it's a GitHub survey and even though it looks like there's a lot of people in the United States contributing to open source at per capita level. Also, Germany is not doing that bad. So our Python community is global. Very few of us had a global upbringing in education. I don't know how many of us moved to five countries by the time we were 16. Because that would mean like a global upbringing to like really go somewhere else, have different people change. So we grew up in little bubbles, right? Most all of us. Humans learn their whole life about other humans and cultures, and we need to accept that we don't know everything about everybody. A lot of us is hidden, and we don't just go to a new stranger and just tell our life story to them instantly, right? And we need to just keep learning and get better. So in my opinion, a code of conduct can be a framework to help us truly communicate globally in a successful way. But it's not like something that, you know, you get it right the first time, it's like, oh, I read the code of conduct, I can now apply it. It takes practice, it takes, you know, wanting to learn. The PSF code of conduct has this quote, I was saying that it's one of the better written, so the Python community is made of members from around the globe with diverse set of of skills, personalities, and experience, and when we are working together, this code of conduct will help us steer your interactions and keep Python a positive, successful, and growing community. And we want basically code of conducts to encode core values and norms in the community, for example, inclusivity, respectfulness, and being open and considerate, and provide guidance to newcomers, And it can also signal to marginalised people that the open source community cares. That also means that when there is no code of conduct, the other signal gets sent, right? So let's talk a little bit about is our code of conduct working or not? How can you tell that your code of conduct is not working? Well, according to the Linux Foundation Survey, the Diversity and Inclusion Survey from 2021, these were the reporting statistics. So apparently, like, I don't know, over 50%... So, yeah, this is not a very good graph. But anyways, so a lot of people reported lack of response or rejection of contributions and questions. So in the Code of Conduct, the PSF, We get a lot of reports about somebody dismissed my issue and just closed the issue and didn't listen to me, and so this is happening, right? Conflict or interpersonal tension between you and another contributor, written or spoken language that made people feel unwelcome, stereotyping, threats of violence, talking, unsolicited sexual advances or comments, impersonation, or malicious publication of personal information. And so whenever we have statistics that say, within this amount of time, we didn't receive any reports, so everything is going on fine, that is not what the data says, that's the distribution, what's going on out there, right? So this actually should be a flag. If you don't have reports, it doesn't mean that everything is going fine. and it actually means that people don't feel safe to report, people don't feel that it's worth reporting, people are not able to report, people are not able to have a positive conversation. So why don't people report? So these are some things that I've noticed. I've noticed poorly written code of conduct. When the code of conduct is written badly, you end up spending like over an hour just reading through all the links and the documentation of the website to find out if your issue what happened to you is a code of conduct situation then you're like so unsure and then in the end you're even doubting yourself and then you're like I don't is this this is and then by the time you're done reading you think you're imagining everything that happened to you so so it's like hard to identify your situation itself and the statements on the code of conduct are going to be vague which when they are dealing with your issue it a lot of things will be up for interpretation i don't know did anybody here in the room feel like this happened to them they reported something somewhere and in the end it was like yeah i don't know it didn't violate anything or it's like you're imagining it or something like that so so this can be really frustrating and it will take a lot of effort on the person who reports to report. And that's usually people give up reporting. Another thing that I've noticed is that many times code of conduct in events, especially in events because these are like appearing, they're happening, you know, and then they don't happen anymore, right? The code of conduct can be treated as a technicality. So we have to have a code of conduct. Yeah, we have to add it to the website. Otherwise, some people will complain, and then they do it for these reasons. Some people say, like, I'm not going to attend an event if it doesn't have a code of conduct, and then they write the organizers, there's no code of conduct, I'm not coming, and then they say, oh, we have to put a code of conduct, somebody complained. So there's ways to not have that. I think with PyLadies meetups, we usually, at every event, at the beginning of the meetup, we talk about code of conduct. it happened also at this conference at the opening session there was talk about the code of conduct was explained everybody was on there now theoretically is on the same page about our expectations of behavior at this conference okay so another thing code of conduct is perceived as annoying like this annoying must have something that gets forgotten added at the end an afterthought and no enforcing committee is set So we have a code of conduct, but we don't do anything with it. It turns out that 30% of the people who filled in the survey from the Linux Foundation, diversity and inclusion survey, are unsure codes of conduct will be enforced. That is a big number. That means there's just no process. Even to the people that have ever applied, they don't even get an email at the end. It's like, oh, we got your report, thank you, we are dealing with this. Or this dialogue that puts people at ease didn't happen. Another thing where I've noticed is conflicts of interest. You may actually have people in the Code of Conduct Committee that are the ones whom the report is about. You know, like, when you have, like, older communities where the founders of the communities are wearing too many hats, they are in the also in the code you know like and you know there's just lack of change and you know the world is changing but some people don't change and then they're everywhere and you can't complain anymore because they would get the report and how can you even report if you know that the person who's you're reporting about is in the committee or friends of the people right so and this is something that people who are like in a code of conduct committee and end up recusing themselves at every meeting because oh I can't have an opinion about this person I can't say my opinion about this person because we're friends and I know and we contributed to code together and I can't say anything and if you recuse yourself most of the time then why are you in that committee you want to be in a committee go to another community and to the code of conduct committee and another thing that's happening and this is why I'm having this talk also to rethink about code of conduct is like people in the community some people not of course not everybody there are some people that think that the role of the code of conduct is to be the police. And I mean, call it a generation divide, it can be all sorts of reasons why this is happening, but this is happening. Even in the Python Software Foundation where the code of conduct committee doesn't have any power, we only recommend actions to the steering council. We don't actually kick people off the mailing list, we don't ban people from contributing to Python, but this is not really understood by the general Python developer community, and we did get... I've seen applications to the steering council where the text of the application was, I will remove some of the power that the code of conduct committee has, because we have now lost some very experts who were contributing, and then they got kicked out because of their behaviour. And again, if you have a good process, we don't have the power to do that, we just recommend. We wouldn't really lose this power, this power doesn't exist anyway to be lost in the first place so how can we get our codes of conduct working so here i have like um the part about writing the code of conduct the text itself and enforcing the code of conduct so these are two things i think that are the two so the writing code of conduct from what i've seen is first you have the values right the values of the community are explicitly mentioned and they represent the members in the community now think about of all the companies I don't know how many of you work in a company do you have values defined in your company top down bottom up I don't know you know there's always mission vision you know sometimes it's room for improvement in some companies but and also in some communities so these values if they're like not transparent that they exist, then how can people like even, you know, use those? So this is basically, these are the values of the Python software foundation code of conduct. Being open, considerate, respectful, and then they're also explained. Then in the end, this whole code of conduct definition, you can like come back to it and then see if any of these values you feel like got, like, crossed. The second part about writing the code of conduct is defining the norms and standards. Like, what are the behaviors that are acceptable and what are the behaviors that are not acceptable? How do you deal with those? You know, what's the process? So here, there are plenty of good examples out there. Nobody today is writing from scratch their code of conduct. I mean, that would be like, you know, it's a lot of work, and it's a lot of collaborative work that all of the codes of conduct out there are at the moment licensed that everybody can use, so they are on free licenses because this is something that everybody wants everybody to get better at. So there's zero reason for this not to be used. So again, from the Python Software Foundation, Again, there's a whole list of what's inappropriate. And it's really easy to say, like, if this, you know, if you, like, stalking is there, you know, I don't have to think about it. Like, I got followed, I don't want to be followed. Logging, like, doxing is public, you know, having language, violent language directed against another person. So all of these things are, the list is longer. this is just a screenshot so all of these things are described explicitly and it's also then easy for you to say okay this was not inclusive um okay so now let's remember the situations where you remember at the beginning of the talk we were talking about the situations so the ideally this code of conduct how it is defined should be helping you with talking about the situations you as a person reporting it should help you better understand what behavior you know putting it in words to explain what was not acceptable about what happened to you but also if you are on the other side you know to understand that you can also think about what are the values a lot of times you need to talk about your feelings and then you're like it's really hard to pinpoint exactly what was that feeling what happened to me and and then it's also something that validates because a lot of the times when something happens to us we are unsure like how many times did something happen to you and then you went for a second opinion to ask whether this was really like do you really think this like am I in the right should I feel offended about this or am I sensitive? Yeah, so this should be with a proper code of conduct, you shouldn't need to ask another person for saying that, yes, you're right. Because our society is teaching us that no, we are not right, so the code of conduct is there to help. And then comes the second part, enforcement. So you have to think about codes of conduct are a glass roots movement. They were not like top down, like the sea level, something decided they want a code of conduct. It was mostly the people, the community self-regulated and said, we need to define our guidelines and we need to say, if you are like also organizing a conference, organizing an event, organizing a community you need to prioritize having a committee at your event so okay you have a code of conduct you found the perfect code of conduct but if that doesn't get enforced then it doesn't matter right because then people complain and nothing happens it's like when somebody says you can give me feedback and they give you feedback and then say and then you're like but i'm not going to use the feedback right so then you don't give feedback so for this then you also need to have a clear process for enforcement that gets defined. And it usually happens that, again, the same like diversity, code of conduct is like an afterthought in many situations. You know, people think about, yeah, we have it, but then it's not really prioritised. And again, all of the stuff that I said before, you need training. It's learnable stuff you and people who are in committees you should expect the like if I see a committee I know that a lot of people have expectations that at least some of the people in the committee have proper training for code of conduct and if you're asking yourself how do I get in code of conduct committees well this is really easy you volunteer because this is like the part that as if it's an afterthought usually in many places people like really close to the event they are scrambling for volunteers oh we don't have a volunteer for the code of conduct so this is perfect opportunity the place where you will always find a spot last month we did a code of conduct enforcement training with other technology with sage so they are actually the ones that are like I think at the moment the the most know-how about code of conduct enforcement and in this training we learned like we discussed how to take an incident report how to listen how to respond to a reported person how to evaluate the report how to collect the data and preserve privacy at the same time because you know you want to make a safe space the code of conduct process should be safe. So I can totally recommend this enforcement training and any other training that SAGE has. And this is my sketch note from the event, but you won't be able to read it here. So closing, I have some community statements. So one of them is from Drew. Drew is in the code of conduct work group with the PSF, and he says, I want to help make it easier for organisations to see why having a strong code of conduct enhances community rather than stifles it. And Noah Tamir, who you've seen keynoting yesterday, they say, I would like to see the code of conduct being used not just for major incidents, but also as a mediation tool for small incidents. And small incidents, for a lot of us, for some people, they are not an incident. For some people, they're like borderline incident. those are like really hard to deal with because you're like hmm yeah i mean you know but this person is doing a hundred borderline incidents per month right so maybe it's not so borderline and or but also small incidents like microaggressions which are also super ambiguous to deal with and helping us in general like talk about things and not just when the house is burning And think about it. The future developers, so this is from GitHub, Python developers, a lot of them, everywhere. Our Python community is global. We need to understand that we truly need to invest in learning how to communicate with each other. You know, we are not born communicators. Like, actually, we don't know how to speak when we're babies, I heard. Here, anybody has babies? they don't know how to talk yet, right? So they learn speaking one language, you know, another language. I mean, ChatGPT is going to solve all our problems, but let's see. And so, yeah. So let's do this together. Improve our communication culture in our communities. And that was it. Thank you for listening to me. And you can reach out to me. This is a quote from Jessica. She's also in the Python Software Foundation Code of Conduct work group and did the workshop and after that posted this about it. So if you have any questions or disagreements or opinions.

Speaker 2 [28:14]

I do appreciate a lot of your thoughts. I have a whole article written just for taking notes. I don't have questions in Slido, but I do have a...

Speaker 3 [28:24]

do have a

Speaker 2 [28:25]

Does anyone here would like to ask a question?

Speaker 3 [28:31]

Yeah, thank you for your interesting talk. Yeah, it's a big topic, obviously. Would you maybe share, I mean, anonymously, of course, some examples where you saw that the reporting certain type of incidents really helped to improve the situation or, like, you've seen, for example, the same person who was reported that it was just different. Like, what I'm trying to say, maybe, do you see the impact of having code of conduct in place? Like, in which areas?

Speaker 1 [29:16]

areas yes I think so I think one of the one of the most visible things that we also dealt with I think with in within the PSF and had a lot of discussions about was the renaming of the master branch to main also in Python and there were very a lot of very upset people and but this also gave a platform for people to be able to be told that they're not right to be upset about. This is not something in 2020 that you should be on that front. And I think there were also some public statements made about this on Python. Other things I think we sometimes get people reaching out who did not have a report against them, them, but someone said you... So they wrote something and then someone said, but you... This is kind of like non-inclusive, how you talk to me according to the code of conduct. So sometimes people without reporting it, but they use the code of conduct in a comment on GitHub, and then this person actually reached out to us for us to explain how, what did they do wrong, you know? So some people are open for this dialogue, so it gets, you know, like, it brings a little bit of visibility that there is a place for this dialogue, and it's moving some people forward. And in the end, it was like, hey, you said this code is useless. When you read it, it has a tone in your head. It's a lot of work for whoever reads the sentence that something is useless to not see it as that tone. So there's that. Of course, sometimes in events, I think in events it's a little bit different. With the Python Software Foundation, we have written reports, but with events, you need to act completely differently, so if something happens, you need to sometimes remove a person from a conference, and that can make a big difference for a lot of other people. So I don't know if you've ever noticed that, or been in a situation where you had to be there, someone it had to be removed from an event. I mean, PyLadies, it's always sometimes something happens in the meetups that are about diverse groups, so I think there we definitely need a code of conduct to have some dialogues.

Speaker 2 [32:15]

We are letting me do the time

Speaker 1 [32:16]

Ta-da-da-da.

Speaker 2 [32:18]

We are kind of over time, but I do have a question about talking about the language. I have two kind of different questions. One is about, don't you think, I have issues with the word enforcement.

Speaker 1 [32:30]

I have serious issues with that.

Speaker 2 [32:31]

We still have issues with that, especially because we are a volunteer base, and even during the training, we're still in a volunteer base. Do you have any thoughts on that?

Speaker 1 [32:42]

Yeah, so I think the word enforcement here is not about that you're enforcing something on somebody. It's more about the process itself, that in order to make sure that the process is fair for everybody, you need to follow some steps. like this is more like it's about how you yes and it's a lot more work right because instead of just having a conversation on the hallway somebody says something happened now you actually have to write it down somewhere in a way that it doesn't fall back to that person getting discriminated or something bad happens to that so there's a lot of reasons why it's or even when you talk to the person that got reported it, you need to have a specific language to give feedback, otherwise it can all explode. So this word enforcement, yes, it sounds very harsh, but it's just, it's not about enforcing it on people, but it's more about the fact that you kind of have to follow a process. And not following a process, in this case, can have a little bit of bad repercussions to different people.

Speaker 2 [34:05]

Thank you, we are really with anyone would like to do some comment or share something So I appreciate a lot of our thoughts and sharing your experience and thank you all for participating

Speaker 1 [34:19]

Thank you.

Tereza Iofciu

Social card for talk: Rethinking codes of conduct