justinmclean opened a new pull request, #3787: URL: https://github.com/apache/iggy/pull/3787
## Which issue does this PR address? N/A ## Rationale Adds a `SECURITY.md` so GitHub points people at the private reporting channel before they open a public issue. Not required by ASF policy, just useful. Reports go to [email protected], as Iggy has no project security list. The rest restates the ASF process: acknowledge, CVE from the ASF Security Team as CNA, fix in private, advisory at release. The "Out of Scope" list is a suggestion and the only part that asserts anything on the project's behalf. Trim or drop it as you see fit. It is short because Iggy has no published security model, unlike Apache Airflow's SECURITY.md, which this is loosely based on. AI was used to help draft this. Reviewed by a human. ## What changed? Added the SECURITY.md file. Also whitelists `CNA` in `.typos.toml`, which otherwise rewrites it to "CAN". ## Local Execution prek run --files SECURITY.md ## AI Usage Claude helped write this, but it was checked and modified by a human. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
