justinmclean opened a new pull request, #3787:
URL: https://github.com/apache/iggy/pull/3787

   ## Which issue does this PR address?
   
   N/A
   
   ## Rationale
   
   Adds a `SECURITY.md` so GitHub points people at the private reporting channel
   before they open a public issue. Not required by ASF policy, just useful.
   
   Reports go to [email protected], as Iggy has no project security list. The
   rest restates the ASF process: acknowledge, CVE from the ASF Security Team as
   CNA, fix in private, advisory at release.
   
   The "Out of Scope" list is a suggestion and the only part that asserts 
anything
   on the project's behalf. Trim or drop it as you see fit. It is short because
   Iggy has no published security model, unlike Apache Airflow's SECURITY.md,
   which this is loosely based on.
   
   AI was used to help draft this. Reviewed by a human.
   
   ## What changed?
   
   Added the SECURITY.md file.
   
   Also whitelists `CNA` in `.typos.toml`, which otherwise rewrites it to "CAN".
   
   ## Local Execution
   
   prek run --files SECURITY.md
   
   ## AI Usage
   
   Claude helped write this, but it was checked and modified by a human.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to