apache / apache/hertzbeat

[BUG] issues with Hertzbeat Security docs

Open
#2,854 5 comments 1 reaction 0 assignees View on GitHub
bug
Dominant language
Java
Stars
7.4k
Forks
1.3k
Avg merge
1d 20h
Merged PRs (30d)
32

Description

### Is there an existing issue for this?

- [X] I have searched the existing issues

### Current Behavior

The link to report a security issue on https://github.com/apache/hertzbeat/issues/new/choose is not ASF standard practice. It is my understanding that all security issues relating to ASF projects and podlings need to be reported to an ASF mailing list. The default is security@apache.org but some well established projects have mailing lists of form security@project-name.apache.org. These mails are visible to the ASF Security team and this allows independent monitoring of whether ASF teams are dealing with reports.

I also think that https://github.com/apache/hertzbeat?tab=security-ov-file#readme should be updated to explicitly link to https://www.apache.org/security/ and to be much more explicit about the need to keep the issue private until the project team gets to look at the issue and if necessary, attempt a fix.

fyi @raboof

### Expected Behavior

Follow standard ASF Security practices

### Steps To Reproduce

_No response_

### Environment

```markdown
HertzBeat version(s):
```

### Debug logs

_No response_

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the repository's GitHub security page at github.com/apache/hertzbeat?tab=security-ov-file#readme and the issue-reporting link at github.com/apache/hertzbeat/issues/new/choose. Compare both with the ASF security guidance at www.apache.org/security/. Done means the reporting path and private-disclosure guidance follow the requested ASF practice.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.