potiuk commented on issue #70676:
URL: https://github.com/apache/airflow/issues/70676#issuecomment-5143302242

   This time I did not hide the issue or it's content becasue if you look at 
our security model, DOS is almost never considered as a security vulnerability 
- read the model and find out why. 
   
   NEVER EVER IN THE FUTURE use "Security issue" in public issue. This is just 
plain wrong and violates our security policy. Repeated violation of those 
policy will casue reporting of such accounts to GitHub and eventually disabling 
them. 
   
   You should **check** if what you report is a security issue by verifying it 
against our Security model. If it's not, this is a regular non-security PR you 
can open - you do not even need to open PR. If you determine - after carefuly 
reading our model - that it's a security issue - follow our Security Policy to 
report it.
   
   And if you are using Agents to make reports and PRS - it's still YOUR 
responsibility to instruct them and review what they are doing so you will bear 
consequences of them doing so.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to