jupyter / jupyter/security

Move/Extend security subproject to the numfocus level.

Open
#6 6 comments 2 reactions 0 assignees View on GitHub
Dominant language
Jupyter Notebook
Stars
27
Forks
12
Avg merge
3d 5h
Merged PRs (30d)
3

Description

This conversation was started a bit on the meeting 8 days ago.

It appear to me that beyond the scope of Securing Jupyter, there are security aspect that could be tackled at the NumFOCUS level.

Indeed, security in a Jupyter environment is not limited to how Jupyter is deployed, but can also be affected by all the packages installed. And if to the core contributors it might be obvious who to contact and which projects are impacted, questions about security or vulnerability disclosure, the point of contact might be unclear.

In practice, there is also monitoring and configuration issue at the Jupyter Level where `security(at)ipython.org`, mails can go to spam, be ignored, or bounce. And the key management is imperfect.

I would like to suggest the following to the NumFOCUS board:

- Create a security working group of subcommittee and `security@numfocus.org` mailing address.
- The sole purpose of this committee at the beginning would be to handle and triage security vulnerability and forward to the right teams/person and followup with publication and disclosure.

To be clear I don't expect people from this committee to decide the best practices about security, or work on fixing the security issue, but to make sure security that there is a single unified point of contact across the PyData ecosystem, and a guaranteed fast acknowledgement of reports.

If we want an actual proposal to numfocus then we need a better document that list exactly what we are asking for, and who would serve on this committee.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.