-
Notifications
You must be signed in to change notification settings - Fork 3.7k
[docs] Clarify security vulnerability process and reporting #17039
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[docs] Clarify security vulnerability process and reporting #17039
Conversation
- the previous description wasn't very clear and could cause confusion
09f55d9 to
7056485
Compare
|
@tisonkun @Anonymitaet @dave2wave @michaeljmarshall please review |
tisonkun
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you!
michaeljmarshall
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. I agree with these changes, and I think it makes sense to have some of the information duplicated across the SECURITY.md and the website. I also think we should make the security page easier to find and that we don't need to include it in the versioned docs.
|
I'm bothered that we have versioned docs about security policies and supported versions. It makes no sense. I would suggest a further PR removes all of these and instead in the versioned menus refers to the common and most current version. |
@dave2wave Yes, that's a problem. I created #17052 to track it. |
Motivation
(that was only visible in https://pulsar.apache.org/docs/next/security-policy-and-supported-versions/)
Modification