alamb opened a new pull request, #25917:
URL: https://github.com/apache/datafusion/pull/25917

   ## Which issue does this PR close?
   
   - Closes #25916.
   
   ## Rationale for this change
   
   As an ASF project, DataFusion should follow the ASF reporting guidelines and 
provide a means for responsible security disclosures.
   
   ## What changes are included in this PR?
   
   Adds a top-level `SECURITY.md` modeled on [arrow-rs's 
SECURITY.md](https://github.com/apache/arrow-rs/blob/main/SECURITY.md) (and the 
similar update made in 
[apache/datafusion-sqlparser-rs#2601](https://github.com/apache/datafusion-sqlparser-rs/pull/2601)).
 It describes:
   - The security model for DataFusion (what counts as a bug vs. a 
vulnerability)
   - Rust safety/soundness/UB considerations
   - How to report ordinary bugs (public issue tracker)
   - How to report vulnerabilities, following the [ASF security reporting 
process](https://www.apache.org/security/#reporting-a-vulnerability) (emailing 
[email protected])
   
   ## What is the testing strategy for this PR?
   
   This is a documentation-only change (`SECURITY.md`). Ran 
`./ci/scripts/doc_prettier_check.sh --write --allow-dirty` to confirm 
formatting; no other changes were needed.
   
   ## Are there any user-facing changes?
   
   Adds a new `SECURITY.md` file at the repository root, visible on GitHub's 
repository page under 'Security'.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to