apache / apache/incubator-seata
[Security Follow-up] Request for status update on private report submitted on August 2, 2026
- Dominant language
- Java
- Stars
- 26k
- Forks
- 8.8k
- Avg merge
- 1d 8h
- Merged PRs (30d)
- 4
Description
### Check Ahead
- [x] I have searched the [issues](https://github.com/seata/seata/issues) of this repository and believe that this is not a duplicate.
- [x] I am willing to try to fix this bug myself.
### Ⅰ. Issue Description
Hello Seata team,
I am writing to respectfully follow up on a private security report that I submitted to the Apache Security Team on August 2, 2026.
Timeline:
- August 2, 2026: Initial private report submitted to security@apache.org, with private@seata.apache.org copied.
- August 31, 2026: Follow-up sent to the Apache Security Team.
- August 31, 2026: A Seata maintainer confirmed that the report had been received and would be coordinated with the PMC.
- September 6, 2026: Follow-up request sent.
- September 9, 2026: Additional follow-up request sent.
- September 14, 2026: I have not yet received a further status update or tracking information.
For reference, I previously opened a status follow-up in #8213:
https://github.com/apache/incubator-seata/issues/8213
I understand that security-related matters may require private handling and coordination. I have followed the ASF responsible-disclosure process and will continue to respect the project’s preferred procedures.
Could you please confirm whether the report is being handled by the appropriate team, and let me know whether any further information or assistance is needed from me?
This report is part of my ongoing research. If you have any questions, please feel free to @mention me at any time. I would be very happy to provide assistance and contribute to improving Seata’s security.
Thank you for your time and assistance.
Best regards,
### Ⅱ. Describe what happened
_No response_
### Ⅲ. Describe what you expected to happen
_No response_
### Ⅳ. How to reproduce it (as minimally and precisely as possible)
_No response_
### Ⅴ. Anything else we need to know?
_No response_
### Ⅵ. Environment
_No response_
Contributor guide
Research direction
Start by reviewing the linked prior follow-up in issue #8213 and the private security-report correspondence referenced in this issue. No source files, tests, or entry points are identified; done means confirming the report's handling or receiving the requested status and tracking information.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100