kafka-site icon indicating copy to clipboard operation
kafka-site copied to clipboard

MINOR: document how we deal with advisories for dependencies

Open raboof opened this issue 2 years ago • 4 comments
trafficstars

We get questions about advisories in dependencies on a regular basis, often in the form of security scanner tool output. Because of the high likelihood of false positives, the ASF policy is not to accept such reports as security issues without additional analysis: we consider the mere fact that an advisory exists for a dependency already public knowledge.

This update makes this clearer to reporters, helps them find out whether an advisory impacts Kafka for themselvels (by pointing to the dependency-check suppressions and the issue tracker), and calls on them to help out with analysis.

raboof avatar Oct 04 '23 09:10 raboof

Thanks @raboof , can you put a description for detailing the purpose of this pull request ?

bmscomp avatar Oct 04 '23 09:10 bmscomp

cc: @mimaison @ijuma @showuon, I would also solicit your opinion on this one.

divijvaidya avatar Oct 04 '23 09:10 divijvaidya

Thanks @raboof , can you put a description for detailing the purpose of this pull request ?

(updated the commit and PR message)

raboof avatar Oct 04 '23 09:10 raboof

@raboof @divijvaidya -- What is the status of this PR? Seems nothing happened for a while. Do we still plant to get this merged, or should we close it?

mjsax avatar Jun 17 '24 15:06 mjsax

I feel comfortable with the current wording on this PR. Will keep this open for another 3 days for others to chime in, else I will merge this one.

divijvaidya avatar Jul 16 '24 12:07 divijvaidya