This is an automated email from the ASF dual-hosted git repository.

rzo1 pushed a commit to branch security-model-expansion
in repository https://gitbox.apache.org/repos/asf/stormcrawler-site.git

commit 1097694a2a9cb8809946925d388c4ea22f9b0ba7
Author: Richard Zowalla <[email protected]>
AuthorDate: Tue Aug 18 19:45:45 2026 +0200

    Normalize line endings in security page to LF
    
    security/index.html was the only file in the repository still using CRLF
    line terminators; every other page uses LF. Converting it in a separate
    commit keeps the content change that follows reviewable as a diff.
    
    Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
---
 security/index.html | 124 ++++++++++++++++++++++++++--------------------------
 1 file changed, 62 insertions(+), 62 deletions(-)

diff --git a/security/index.html b/security/index.html
index 8156457..b0bdd02 100644
--- a/security/index.html
+++ b/security/index.html
@@ -1,62 +1,62 @@
----
-layout: default
-slug: security
-title: Reporting Security Problems to Apache StormCrawler
----
-
-<div class="row row-col">
-       <h1>Security</h1>
-       <h2>Reporting New Security Problems with Apache StormCrawler</h2>
-       <p>The Apache Software Foundation takes a very active stance in 
eliminating security problems and denial of service attacks against its 
products.</p>
-       <p>We strongly encourage people to report security problems privately 
using the security mailing list of the <a 
href="https://www.apache.org/security/";>ASF Security Team</a> before disclosing 
them in a public forum.</p>
-       <p>Please note that the security mailing list should only be used for 
reporting undisclosed security vulnerabilities and managing the process of 
fixing such vulnerabilities. We cannot accept regular bug reports or other 
queries at this address. All mail sent to this address that does not relate to 
an undisclosed security problem in our source code will be ignored.</p>
-       <p>The private security mailing address is: <a class="externalLink" 
href="mailto:[email protected]";>[email protected]</a></p>
-
-       <h2>Threat Model and Security Considerations</h2>
-       <p>StormCrawler is designed to operate in trusted environments as part 
of a distributed Apache Storm&reg; cluster. This document outlines the threat 
model and key security assumptions to help users understand the secure use and 
deployment of StormCrawler.</p>
-
-       <h3>Trusted Configuration</h3>
-       <p>The configuration file used by StormCrawler is loaded during 
topology submission and is treated as a trusted source. It does not involve any 
user-supplied input at runtime.</p>
-       <p>If an attacker is able to modify this file, they would already have 
full access to the system, including:</p>
-       <ul>
-               <li>The ability to alter behavior of the topology</li>
-               <li>Access to credentials and other secrets</li>
-               <li>Arbitrary control over job execution</li>
-       </ul>
-       <p>Securing the configuration file and the environment in which 
topologies are submitted is essential. However, modification of the file 
implies full system compromise and is out of scope for runtime protections.</p>
-
-       <h3>Apache Storm&reg; Cluster Security</h3>
-       <p>StormCrawler runs on an Apache Storm&reg; cluster, which is designed 
to allow users to:</p>
-       <ul>
-               <li>Submit topologies</li>
-               <li>Execute custom, user-defined code</li>
-       </ul>
-       <p>This model inherently trusts cluster users and assumes they are 
authorized.</p>
-
-       <h4>Security Recommendations:</h4>
-       <ul>
-               <li>Access to the Apache Storm&reg; cluster must be strictly 
restricted to trusted users</li>
-               <li>Underlying systems should not store secrets or hold 
elevated privileges beyond those assigned to the authorized users</li>
-               <li>Avoid deploying StormCrawler in multi-tenant environments 
without strong isolation guarantees</li>
-       </ul>
-
-       <h3>Summary</h3>
-       <p>StormCrawler's security model assumes a trusted deployment 
environment. Users should:</p>
-       <ul>
-               <li>Secure configuration files and deployment 
infrastructure</li>
-               <li>Restrict Apache Storm&reg; cluster access</li>
-               <li>Follow best practices for secret and privilege 
management</li>
-       </ul>
-
-       <h2>Asking Questions About Known Security Problems</h2>
-       <p>Questions about:</p>
-       <ul>
-               <li>if a vulnerability applies to your particular 
application</li>
-               <li>obtaining further information on a published 
vulnerability</li>
-               <li>availability of patches and/or new releases</li>
-       </ul>
-       <p>should be addressed to the <a 
href="https://lists.apache.org/[email protected]";>dev 
mailing list</a>.</p>
-
-       <h2>Known Security Vulnerabilities</h2>
-       <p>No known security vulnerability yet.</p>
-</div>
+---
+layout: default
+slug: security
+title: Reporting Security Problems to Apache StormCrawler
+---
+
+<div class="row row-col">
+       <h1>Security</h1>
+       <h2>Reporting New Security Problems with Apache StormCrawler</h2>
+       <p>The Apache Software Foundation takes a very active stance in 
eliminating security problems and denial of service attacks against its 
products.</p>
+       <p>We strongly encourage people to report security problems privately 
using the security mailing list of the <a 
href="https://www.apache.org/security/";>ASF Security Team</a> before disclosing 
them in a public forum.</p>
+       <p>Please note that the security mailing list should only be used for 
reporting undisclosed security vulnerabilities and managing the process of 
fixing such vulnerabilities. We cannot accept regular bug reports or other 
queries at this address. All mail sent to this address that does not relate to 
an undisclosed security problem in our source code will be ignored.</p>
+       <p>The private security mailing address is: <a class="externalLink" 
href="mailto:[email protected]";>[email protected]</a></p>
+
+       <h2>Threat Model and Security Considerations</h2>
+       <p>StormCrawler is designed to operate in trusted environments as part 
of a distributed Apache Storm&reg; cluster. This document outlines the threat 
model and key security assumptions to help users understand the secure use and 
deployment of StormCrawler.</p>
+
+       <h3>Trusted Configuration</h3>
+       <p>The configuration file used by StormCrawler is loaded during 
topology submission and is treated as a trusted source. It does not involve any 
user-supplied input at runtime.</p>
+       <p>If an attacker is able to modify this file, they would already have 
full access to the system, including:</p>
+       <ul>
+               <li>The ability to alter behavior of the topology</li>
+               <li>Access to credentials and other secrets</li>
+               <li>Arbitrary control over job execution</li>
+       </ul>
+       <p>Securing the configuration file and the environment in which 
topologies are submitted is essential. However, modification of the file 
implies full system compromise and is out of scope for runtime protections.</p>
+
+       <h3>Apache Storm&reg; Cluster Security</h3>
+       <p>StormCrawler runs on an Apache Storm&reg; cluster, which is designed 
to allow users to:</p>
+       <ul>
+               <li>Submit topologies</li>
+               <li>Execute custom, user-defined code</li>
+       </ul>
+       <p>This model inherently trusts cluster users and assumes they are 
authorized.</p>
+
+       <h4>Security Recommendations:</h4>
+       <ul>
+               <li>Access to the Apache Storm&reg; cluster must be strictly 
restricted to trusted users</li>
+               <li>Underlying systems should not store secrets or hold 
elevated privileges beyond those assigned to the authorized users</li>
+               <li>Avoid deploying StormCrawler in multi-tenant environments 
without strong isolation guarantees</li>
+       </ul>
+
+       <h3>Summary</h3>
+       <p>StormCrawler's security model assumes a trusted deployment 
environment. Users should:</p>
+       <ul>
+               <li>Secure configuration files and deployment 
infrastructure</li>
+               <li>Restrict Apache Storm&reg; cluster access</li>
+               <li>Follow best practices for secret and privilege 
management</li>
+       </ul>
+
+       <h2>Asking Questions About Known Security Problems</h2>
+       <p>Questions about:</p>
+       <ul>
+               <li>if a vulnerability applies to your particular 
application</li>
+               <li>obtaining further information on a published 
vulnerability</li>
+               <li>availability of patches and/or new releases</li>
+       </ul>
+       <p>should be addressed to the <a 
href="https://lists.apache.org/[email protected]";>dev 
mailing list</a>.</p>
+
+       <h2>Known Security Vulnerabilities</h2>
+       <p>No known security vulnerability yet.</p>
+</div>

Reply via email to