Re: CVE reports and process to completion

2023-09-19 Thread Stamatis Zampetakis
Many thanks to Ayush for volunteering! Anyone else? Note that handling vulnerabilities is of utmost importance to an Apache project. It is one of the four technical requirements established by ASF [1]. If there are not enough PMC members to handle CVEs the project can be taken down. Best, Stamati

Re: CVE reports and process to completion

2023-09-13 Thread Ayush Saxena
Hi Stamatis, Thanx for starting the thread, I can volunteer as well. -Ayush On Tue, 12 Sept 2023 at 13:43, Stamatis Zampetakis wrote: > > Hey everyone, > > When someone discovers a potential security vulnerability for Hive (or > any other Apache project) they can opt to inform the PMC of the > p

CVE reports and process to completion

2023-09-12 Thread Stamatis Zampetakis
Hey everyone, When someone discovers a potential security vulnerability for Hive (or any other Apache project) they can opt to inform the PMC of the project by following the ASF guidelines [1]. For Hive, the report should be sent to secur...@hive.apache.org. Next, the PMC follows the steps outlin