[
https://issues.apache.org/jira/browse/YUNIKORN-3457?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18117685#comment-18117685
]
Wilfred Spiegelenburg commented on YUNIKORN-3457:
-------------------------------------------------
The base file with the reporting details is added by the security team based on
the creation of the security mailing list.
We still need to add the security model to that file.
> Add SECURITY.md to document vulnerability reporting process and security
> model for yunikorn-core
> ------------------------------------------------------------------------------------------------
>
> Key: YUNIKORN-3457
> URL: https://issues.apache.org/jira/browse/YUNIKORN-3457
> Project: Apache YuniKorn
> Issue Type: Improvement
> Components: core - common
> Reporter: Mit Desai
> Assignee: Mit Desai
> Priority: Major
>
> yunikorn-core currently has no security documentation. As per ASF guidance on
> documenting a project's security model
> ([https://cwiki.apache.org/confluence/spaces/SECURITY/pages/308153000/Documenting+your+security+model]),
> projects should publish the assumptions and guarantees they make with
> respect to security, so operators can deploy safely and maintainers can
> quickly triage whether an incoming report is a real vulnerability or expected
> behavior. yunikorn-core has several documented-but-unwritten assumptions
> worth capturing explicitly — e.g. the REST/web service on :9080 ships with no
> authentication, authorization, or TLS; Access-Control-Allow-Origin: * is set
> on all responses; and the scheduler core trusts the submitter identity
> (UserGroupInformation) asserted by the Resource Manager without independent
> verification.
> We need to add a SECURITY.md at the repository root containing:
> * A private vulnerability-reporting policy pointing to
> [email protected]
> * A documented security model: scope boundaries relative to sibling repos
> (yunikorn-k8shim, yunikorn-web, yunikorn-scheduler-interface,
> yunikorn-release, yunikorn-site), deployment trust assumptions, the REST
> API's endpoint sensitivity,
> ACL/authorization semantics, user/group and LDAP resolution, logging caveats,
> and a "not secure by default" note on service-account/RBAC scoping.
> * A triage table listing recurring non-findings (e.g. unauthenticated :9080,
> exposed pprof, LDAP Insecure option) with the reasoning for why each is out
> of scope, and what would make it in scope — to reduce noise from scanners and
> AI-assisted
> reports.
> * A "Supported Versions" section pointing to the project download page
> rather than asserting an unstated support policy.
> This will be the first SECURITY.md in the Apache YuniKorn project family and
> is intended to serve as a reference for the sibling repositories to adapt.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]