alamb commented on code in PR #2601:
URL: 
https://github.com/apache/datafusion-sqlparser-rs/pull/2601#discussion_r4148710388


##########
SECURITY.md:
##########
@@ -19,6 +19,41 @@
 
 # Security Policy
 
+This document outlines the security model for `sqlparser-rs` and how to
+report vulnerabilities.
+
+## Security Model
+
+`sqlparser-rs` parses SQL text, which is often untrusted input (e.g., a query
+string from a user or external system). The parser is expected to reject 
invalid
+or malformed SQL with an error.
+
+Unexpected behavior triggered by malformed or adversarial input is generally

Review Comment:
   This very much follows the arrow-rs model -- I am not sure we need to expand 
the scope for SQLParser but am open to suggestions



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to