[BUG] issues with Hertzbeat Security docs
- Dominant language
- Java
- Stars
- 7.4k
- Forks
- 1.3k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 32
Description
### Is there an existing issue for this?
- [X] I have searched the existing issues
### Current Behavior
The link to report a security issue on https://github.com/apache/hertzbeat/issues/new/choose is not ASF standard practice. It is my understanding that all security issues relating to ASF projects and podlings need to be reported to an ASF mailing list. The default is security@apache.org but some well established projects have mailing lists of form security@project-name.apache.org. These mails are visible to the ASF Security team and this allows independent monitoring of whether ASF teams are dealing with reports.
I also think that https://github.com/apache/hertzbeat?tab=security-ov-file#readme should be updated to explicitly link to https://www.apache.org/security/ and to be much more explicit about the need to keep the issue private until the project team gets to look at the issue and if necessary, attempt a fix.
fyi @raboof
### Expected Behavior
Follow standard ASF Security practices
### Steps To Reproduce
_No response_
### Environment
```markdown
HertzBeat version(s):
```
### Debug logs
_No response_
### Anything else?
_No response_
Contributor guide
Research direction
Start by reviewing the repository's GitHub security page at github.com/apache/hertzbeat?tab=security-ov-file#readme and the issue-reporting link at github.com/apache/hertzbeat/issues/new/choose. Compare both with the ASF security guidance at www.apache.org/security/. Done means the reporting path and private-disclosure guidance follow the requested ASF practice.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100