Move/Extend security subproject to the numfocus level.
- Dominant language
- Jupyter Notebook
- Stars
- 27
- Forks
- 12
- Avg merge
- 3d 5h
- Merged PRs (30d)
- 3
Description
This conversation was started a bit on the meeting 8 days ago.
It appear to me that beyond the scope of Securing Jupyter, there are security aspect that could be tackled at the NumFOCUS level.
Indeed, security in a Jupyter environment is not limited to how Jupyter is deployed, but can also be affected by all the packages installed. And if to the core contributors it might be obvious who to contact and which projects are impacted, questions about security or vulnerability disclosure, the point of contact might be unclear.
In practice, there is also monitoring and configuration issue at the Jupyter Level where `security(at)ipython.org`, mails can go to spam, be ignored, or bounce. And the key management is imperfect.
I would like to suggest the following to the NumFOCUS board:
- Create a security working group of subcommittee and `security@numfocus.org` mailing address.
- The sole purpose of this committee at the beginning would be to handle and triage security vulnerability and forward to the right teams/person and followup with publication and disclosure.
To be clear I don't expect people from this committee to decide the best practices about security, or work on fixing the security issue, but to make sure security that there is a single unified point of contact across the PyData ecosystem, and a guaranteed fast acknowledgement of reports.
If we want an actual proposal to numfocus then we need a better document that list exactly what we are asking for, and who would serve on this committee.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.