Skip to content

docs: add SECURITY.md describing the reporting process and security model - #944

Open
elijahbenizzy wants to merge 1 commit into
mainfrom
docs/security-policy
Open

elijahbenizzy wants to merge 1 commit into
mainfrom
docs/security-policy

Conversation

@elijahbenizzy

Copy link
Copy Markdown
Contributor

Adds SECURITY.md following the ASF guidance on documenting a project's security model: how to report, which versions get fixes, the trust boundaries the project assumes (persisted state, expressions, serialization, tracking server, identifiers, dependencies), what is out of scope, and hardening recommendations for operators. Linked from the README and a short docs/security.rst.

Merge after the tracking identifier validation change, which this document describes as a guarantee.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/website burr.apache.org website

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant