Help requested: Zeppelin Security triage and follow-up

2024-01-31 Thread Apache Security Team
Dear Zeppelin community,

As you know, the Apache Software Foundation really cares about our users'
security, and protects them by defining sensible release and security
processes. These indirectly also protect our committers, shielding
individuals from personal liability. Additionally, we have a security
committee to assist PMCs with the process of triage and followup. Some of
this process is necessarily done in private; as we practice responsible
disclosure.

We see potential security issues are being reported privately to the
Zeppelin PMC, but the PMC is struggling to triage (and, if necessary, fix
and disclose) them in a timely manner. If we cannot turn this trend around
soon, Zeppelin will have to start the Apache Attic process.

On behalf of the PMC: would anyone be interested in significantly helping
out here? If so, please contact priv...@zeppelin.apache.org with
secur...@apache.org in Cc.


Kind regards,

The ASF Security Team


Help requested: Zeppelin security triage and followup

2025-04-10 Thread Apache Security Team
Dear Zeppelin users and developers,

As you know, the Apache Software Foundation takes our users' security
seriously, and defines sensible release and security processes to make sure
potential security issues are dealt with responsibly. These indirectly also
protect our committers, shielding individuals from personal liability. Some
of this process is necessarily done in private; as we practice responsible
disclosure.

We are seeing potential security issues are reported privately to the
Zeppelin PMC, but the PMC currently does not appear to have the bandwidth
to triage (and, if necessary, fix and disclose) them.

On behalf of the PMC: would anyone be interested in helping out here? If
so, please contact priv...@zeppelin.apache.org with secur...@apache.org in
Cc.

If you’re using this project in a professional capacity, now would be a
good time to campaign to allocate time to participate to keep the project
healthy. This is the first step of our more formal security escalation
process[0]. If the Zeppelin project cannot return to a healthy cadence of
dealing with security issues, the only responsible decision for the PMC
(which is collectively responsible for the oversight of the project) would
be to initiate the move to the Attic [1]. Of course we hope this can be
prevented.

As this message is going to the public mailinglist, please do not share
sensitive information in this thread.


Kind regards,

The ASF Security Team

[0]
https://cwiki.apache.org/confluence/display/SECURITY/Project+Security+Response+Formal+Escalation

[1] https://attic.apache.org/