hubcio commented on code in PR #3787:
URL: https://github.com/apache/iggy/pull/3787#discussion_r3702127845


##########
SECURITY.md:
##########
@@ -0,0 +1,62 @@
+# Security Policy
+
+Apache Iggy (Incubating) follows the [Apache Software Foundation security 
process](https://www.apache.org/security/).
+Please read this before reporting anything you believe is a security issue.
+
+## Reporting a Vulnerability
+
+**Do not report security vulnerabilities through public channels.** That means 
no GitHub issues, pull
+requests or discussions, no Discord, and no social media. Public disclosure 
before a fix is available
+puts users at risk.
+
+Send reports to **[[email protected]](mailto:[email protected])**.
+
+Iggy does not currently have its own project security list, so 
`[email protected]` is the correct
+address. The ASF Security Team will forward your report to the Iggy PPMC's 
private list and confirm to
+you that they have done so.
+
+When reporting, please:
+
+- send one plain-text, unencrypted email per vulnerability
+- describe the issue in the body rather than attaching images, video, HTML or 
PDF
+- include the affected version or commit, the component (server, SDK and 
language, CLI, connector,

Review Comment:
   nit: "the component (server, SDK and language, CLI, ...)" reads as one 
garbled item. Reword to "SDK (and which language)".



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to