slfan1989 commented on PR #8706: URL: https://github.com/apache/hadoop/pull/8706#issuecomment-5467312848
@steveloughran Hi Steve, could I ask for your advice on how we should handle [PR #8706] The PR describes a potential command-execution issue across a privilege boundary. According to Hadoop’s `SECURITY.md`, an unfixed vulnerability should normally be reported privately rather than through a public PR or JIRA. Should we ask the author to contact `[email protected]` and continue the technical discussion privately? Should the current PR be closed or otherwise handled differently until the security team completes its triage? Alternatively, has this issue already been assessed as a normal bug that can continue through the public workflow? Thanks for your guidance. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
