ppkarwasz opened a new pull request, #8616:
URL: https://github.com/apache/hbase/pull/8616

   Congratulations! 💯 Now that you have your very own private security mailing 
list, this PR will help you update the mentions of [email protected] 
throughout your documentation. On our side, we have updated your security 
contact in apache/security-site#95.
   
   This PR points every reporting instruction at the new 
[email protected] list:
   
   - `SECURITY.md` and `AGENTS.md` now name the project list instead of 
[email protected], and note that the ASF Security Team is copied on it and 
that the standard ASF disclosure process applies.
   - The [security model](https://hbase.apache.org/security-model/) page uses 
the new list in its reporting section and in the "what is considered a 
vulnerability" section.
   - The reference guide's preface and Security chapter used to send reports to 
[email protected], which reaches the whole PMC rather than the security 
team. Both now point at the security list. The Security chapter's sentence 
about GPG-encrypted reports to the ASF list is dropped.
   - The legacy `book.html` gets the same replacement, so old bookmarks keep 
giving correct instructions.
   - The mailing-lists page gains a "Security List" row with a Post link and a 
short note that the list is private and reserved for vulnerability reports.
   
   All `mailto:` links to the security list carry a `[SECURITY]` subject, which 
helps the security team tell genuine reports from spam.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to