Skip to content

[docs] Clarify security vulnerability process and reporting - #17039

Merged
codelipenghui merged 2 commits into
apache:masterfrom
lhotari:lh-clarify-security-vulnerability-reporting
Aug 11, 2022
Merged

[docs] Clarify security vulnerability process and reporting#17039
codelipenghui merged 2 commits into
apache:masterfrom
lhotari:lh-clarify-security-vulnerability-reporting

Conversation

@lhotari

@lhotari lhotari commented Aug 10, 2022

Copy link
Copy Markdown
Member

Motivation

Modification

  • Clarify the security vulnerability process and reporting
  • Add information also to SECURITY.md so that the information is available also in cases when pulsar.apache.org isn't reachable or the reader doesn't click on links to read the relevant information. It's better to duplicate information about the vulnerability handling process in SECURITY.md.

@lhotari lhotari added the doc Your PR contains doc changes, no matter whether the changes are in markdown or code files. label Aug 10, 2022
@lhotari lhotari self-assigned this Aug 10, 2022
- the previous description wasn't very clear and could cause confusion
@lhotari
lhotari force-pushed the lh-clarify-security-vulnerability-reporting branch from 09f55d9 to 7056485 Compare August 10, 2022 09:06
@lhotari

lhotari commented Aug 10, 2022

Copy link
Copy Markdown
Member Author

related to #14610 and #16962 (fix for #16919 which was caused by #14610 changes)

@lhotari

lhotari commented Aug 10, 2022

Copy link
Copy Markdown
Member Author

@tisonkun @Anonymitaet @dave2wave @michaeljmarshall please review

@tisonkun tisonkun left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@michaeljmarshall michaeljmarshall left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I agree with these changes, and I think it makes sense to have some of the information duplicated across the SECURITY.md and the website. I also think we should make the security page easier to find and that we don't need to include it in the versioned docs.

Comment thread SECURITY.md
@dave2wave

Copy link
Copy Markdown
Member

I'm bothered that we have versioned docs about security policies and supported versions. It makes no sense. I would suggest a further PR removes all of these and instead in the versioned menus refers to the common and most current version.

@lhotari

lhotari commented Aug 10, 2022

Copy link
Copy Markdown
Member Author

I'm bothered that we have versioned docs about security policies and supported versions. It makes no sense. I would suggest a further PR removes all of these and instead in the versioned menus refers to the common and most current version.

@dave2wave Yes, that's a problem. I created #17052 to track it.

@lhotari
lhotari requested a review from dave2wave August 10, 2022 19:11
momo-jun added a commit that referenced this pull request Sep 7, 2022
* Sync recent changes from #17030, #17039, #16315, and #17057

* fix #17119

* minor updates

* add link of release notes to navigation

* fix

* update release process as per PIP-190

* minor fix

* minor fix

* Update release-process.md
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

doc Your PR contains doc changes, no matter whether the changes are in markdown or code files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] [Doc] no advice on how to report vulnerabilities

5 participants