Skip to content

docs(security): add SECURITY.md with ASF reporting process - #3787

Open
justinmclean wants to merge 2 commits into
apache:masterfrom
justinmclean:add-security-policy
Open

docs(security): add SECURITY.md with ASF reporting process#3787
justinmclean wants to merge 2 commits into
apache:masterfrom
justinmclean:add-security-policy

Conversation

@justinmclean

Copy link
Copy Markdown
Member

Which issue does this PR address?

N/A

Rationale

Adds a SECURITY.md so GitHub points people at the private reporting channel
before they open a public issue. Not required by ASF policy, just useful.

Reports go to security@apache.org, as Iggy has no project security list. The
rest restates the ASF process: acknowledge, CVE from the ASF Security Team as
CNA, fix in private, advisory at release.

The "Out of Scope" list is a suggestion and the only part that asserts anything
on the project's behalf. Trim or drop it as you see fit. It is short because
Iggy has no published security model, unlike Apache Airflow's SECURITY.md,
which this is loosely based on.

AI was used to help draft this. Reviewed by a human.

What changed?

Added the SECURITY.md file.

Also whitelists CNA in .typos.toml, which otherwise rewrites it to "CAN".

Local Execution

prek run --files SECURITY.md

AI Usage

Claude helped write this, but it was checked and modified by a human.

@github-actions

github-actions Bot commented Aug 1, 2026

Copy link
Copy Markdown

Thanks for the PR. It is labeled S-waiting-on-review and queued for review.

Slash commands (own line, regular comment) move it around the queue:

  • /ready - back to S-waiting-on-review after addressing feedback
  • /author - flip to S-waiting-on-author while you finish changes
  • /request-review @user-or-team - request a reviewer

See CONTRIBUTING.md for details.

@github-actions github-actions Bot added the S-waiting-on-review PR is waiting on a reviewer label Aug 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-review PR is waiting on a reviewer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants