sbp commented on issue #1128:
URL: 
https://github.com/apache/tooling-trusted-releases/issues/1128#issuecomment-4499642254

   From the original issue submission:
   
   > While this is committee/project membership metadata (not credentials), 
ASVS 14.2.2 requires cached data be 'securely purged after use'
   
   This is incorrect. ASVS [requires that _sensitive_ data be securely purged 
after use](https://asvs.ee/#v5.0.0-14.2.2):
   
   > Verify that the application prevents sensitive data from being cached in 
server components, such as load balancers and application caches, or ensures 
that the data is securely purged after use.
   
   Committee membership data is not sensitive, so this is not a valid security 
issue. We should still fix the memory leak, but it's a very slow leak so it's 
very low priority.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to