alamb opened a new pull request, #25917: URL: https://github.com/apache/datafusion/pull/25917
## Which issue does this PR close? - Closes #25916. ## Rationale for this change As an ASF project, DataFusion should follow the ASF reporting guidelines and provide a means for responsible security disclosures. ## What changes are included in this PR? Adds a top-level `SECURITY.md` modeled on [arrow-rs's SECURITY.md](https://github.com/apache/arrow-rs/blob/main/SECURITY.md) (and the similar update made in [apache/datafusion-sqlparser-rs#2601](https://github.com/apache/datafusion-sqlparser-rs/pull/2601)). It describes: - The security model for DataFusion (what counts as a bug vs. a vulnerability) - Rust safety/soundness/UB considerations - How to report ordinary bugs (public issue tracker) - How to report vulnerabilities, following the [ASF security reporting process](https://www.apache.org/security/#reporting-a-vulnerability) (emailing [email protected]) ## What is the testing strategy for this PR? This is a documentation-only change (`SECURITY.md`). Ran `./ci/scripts/doc_prettier_check.sh --write --allow-dirty` to confirm formatting; no other changes were needed. ## Are there any user-facing changes? Adds a new `SECURITY.md` file at the repository root, visible on GitHub's repository page under 'Security'. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
