Re: Flink Release Security Workflow

2020-03-20 Thread Robert Metzger
Hey Mark, thanks a lot for reaching out. There is no dedicated security workflow for a Flink release. This is the guide for creating a Flink release (for Flink committers, not for just building Flink locally): https://cwiki.apache.org/confluence/display/FLINK/Creating+a+Flink+Release As part of the

Flink Release Security Workflow

2020-03-18 Thread Mark Hapner
Are there any docs/links that describe the security workflow for a Flink release? For instance, the static code scan workflow; pen test workflow; security review of new features; etc. The reason for the question is to better understand how to include Flink within the security workflow of a prod