Update reporting a vulnerability documentation - #21
Conversation
|
I think one place (below) is enough since we do not want duplicated content, right? @D-2-Ed @DaveDuggins |
|
@Anonymitaet - I agree that we should probably avoid complete duplication. However, I'll note that the Apache Spark project does point to their "Reporting a Vulnerability" page from the mailing list page. See https://spark.apache.org/community.html and https://spark.apache.org/security.html |
|
@michaeljmarshall thanks for your explanations, but we do not need to follow the "Spark way" 😄 |
|
@Anonymitaet - I did not mean to suggest that we should follow their way blindly. In my view, we should make this contact information easy to find, even if it is slightly redundant. I shared the Apache Spark page because it shows the design I have in mind. My main point is that the contact page should include information on how to report a vulnerability or it should link a user to that part of our website. Given that our "report a vulnerability" protocol is primarily "send an email to security@apache.org", I think it makes sense on the contact page where we have all relevant Pulsar email addresses. Beside the obvious benefit of helping security researchers know our protocol, this also ensures that users will notice that we have a well defined security protocol in place. Note that in some of the examples you shared, the community and the contact pages were joined. I agree with you that it wouldn't make sense to have the information in two places if they shared a single webpage. What is your perspective? Thanks. |
|
@michaeljmarshall thanks for your explanations! That makes sense. |
|
@michaeljmarshall @Anonymitaet Any new progress? If there is no agreement within 3 days, I will close this PR, PTAL, thanks. |
|
@Anonymitaet - that is a good solution. In looking at making the change, I noticed that I cannot update the table without also adding links for "subscribe", "unsubscribe", and "archives". Do you know of a way around that? Thanks! |
Sorry, I do not know. If that can not fit into the table, consider adding a paragraph after the table? |
|
Make the names of the list links to the archives. (https://lists.apache.org/list.html?dev@pulsar.apache.org) On the mailing lists page there is a subscribe button. It won't be translated, but ... |
|
I'm going to follow up this thread. With point out all this entrypoint to a new security page and add |
|
Closing... Superseded by #345. You're welcome to give it a review. |




See apache/pulsar#14610 and apache/pulsar#14610 (comment) for context.
Adding some detail to the reporting a vulnerability documentation.
@Anonymitaet - I noticed that we have a contact page on the new website https://pulsar-next.staged.apache.org/contact/. I propose adding this contact information on both pages (the "how to contribute" page and the "contact" page).