Skip to content

Update reporting a vulnerability documentation - #21

Closed
michaeljmarshall wants to merge 1 commit into
apache:mainfrom
michaeljmarshall:update-vulnerability-reporting
Closed

Update reporting a vulnerability documentation#21
michaeljmarshall wants to merge 1 commit into
apache:mainfrom
michaeljmarshall:update-vulnerability-reporting

Conversation

@michaeljmarshall

Copy link
Copy Markdown
Member

See apache/pulsar#14610 and apache/pulsar#14610 (comment) for context.

Adding some detail to the reporting a vulnerability documentation.

@Anonymitaet - I noticed that we have a contact page on the new website https://pulsar-next.staged.apache.org/contact/. I propose adding this contact information on both pages (the "how to contribute" page and the "contact" page).

@michaeljmarshall

Copy link
Copy Markdown
Member Author

I verified that this "looks" correct. Here are screenshots:
Screen Shot 2022-03-15 at 12 20 37 AM
Screen Shot 2022-03-15 at 12 21 01 AM

@Anonymitaet

Copy link
Copy Markdown
Member

I think one place (below) is enough since we do not want duplicated content, right? @D-2-Ed @DaveDuggins

image

@michaeljmarshall

Copy link
Copy Markdown
Member Author

@Anonymitaet - I agree that we should probably avoid complete duplication. However, I'll note that the Apache Spark project does point to their "Reporting a Vulnerability" page from the mailing list page.

See https://spark.apache.org/community.html and https://spark.apache.org/security.html

@Anonymitaet

Copy link
Copy Markdown
Member

@michaeljmarshall thanks for your explanations, but we do not need to follow the "Spark way" 😄

@michaeljmarshall

Copy link
Copy Markdown
Member Author

@Anonymitaet - I did not mean to suggest that we should follow their way blindly.

In my view, we should make this contact information easy to find, even if it is slightly redundant. I shared the Apache Spark page because it shows the design I have in mind.

My main point is that the contact page should include information on how to report a vulnerability or it should link a user to that part of our website. Given that our "report a vulnerability" protocol is primarily "send an email to security@apache.org", I think it makes sense on the contact page where we have all relevant Pulsar email addresses.

Beside the obvious benefit of helping security researchers know our protocol, this also ensures that users will notice that we have a well defined security protocol in place.

Note that in some of the examples you shared, the community and the contact pages were joined. I agree with you that it wouldn't make sense to have the information in two places if they shared a single webpage.

What is your perspective? Thanks.

@urfreespace
urfreespace requested a review from Anonymitaet March 21, 2022 08:44
@Anonymitaet

Copy link
Copy Markdown
Member

@michaeljmarshall thanks for your explanations! That makes sense.
To avoid duplication and add references, how about changing it as below?
(add a row for security@apache.org in the Mailing Lists table)
image

@urfreespace

Copy link
Copy Markdown
Member

@michaeljmarshall @Anonymitaet Any new progress? If there is no agreement within 3 days, I will close this PR, PTAL, thanks.

@michaeljmarshall

Copy link
Copy Markdown
Member Author

@Anonymitaet - that is a good solution. In looking at making the change, I noticed that I cannot update the table without also adding links for "subscribe", "unsubscribe", and "archives". Do you know of a way around that? Thanks!

@Anonymitaet

Anonymitaet commented Mar 24, 2022

Copy link
Copy Markdown
Member

@Anonymitaet - that is a good solution. In looking at making the change, I noticed that I cannot update the table without also adding links for "subscribe", "unsubscribe", and "archives". Do you know of a way around that? Thanks!

Sorry, I do not know. If that can not fit into the table, consider adding a paragraph after the table?

@urfreespace urfreespace closed this Apr 1, 2022
@urfreespace urfreespace reopened this Apr 1, 2022
@dave2wave

Copy link
Copy Markdown
Member

Make the names of the list links to the archives. (https://lists.apache.org/list.html?dev@pulsar.apache.org)

On the mailing lists page there is a subscribe button. It won't be translated, but ...

@tisonkun

Copy link
Copy Markdown
Member

I'm going to follow up this thread. With point out all this entrypoint to a new security page and add Security advisories from the main repo wiki.

@tisonkun tisonkun mentioned this pull request Dec 27, 2022
@tisonkun

Copy link
Copy Markdown
Member

Closing...

Superseded by #345. You're welcome to give it a review.

@tisonkun tisonkun closed this Dec 27, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants