slfan1989 commented on PR #8706:
URL: https://github.com/apache/hadoop/pull/8706#issuecomment-5467312848

   @steveloughran Hi Steve, could I ask for your advice on how we should handle 
[PR #8706]
   
   The PR describes a potential command-execution issue across a privilege 
boundary. 
   According to Hadoop’s `SECURITY.md`, an unfixed vulnerability should 
normally be reported privately rather than through a public PR or JIRA.
   Should we ask the author to contact `[email protected]` and 
continue the technical discussion privately? Should the current PR be closed or 
otherwise handled differently until the security team completes its triage? 
Alternatively, has this issue already been assessed as a normal bug that can 
continue through the public workflow?
   
   Thanks for your guidance.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to