Re: [PR] Add SECURITY.md per dev-list discussion [tomcat ]

csutherl (via GitHub) <[email protected]>
Newsgroups gmane.comp.jakarta.tomcat.devel
Message-ID <PR_kwDOACYN0M7W1o-d-a691fe02-965e-47af-b432-6c08a5ff9aea@gitbox.apache.org>
csutherl commented on code in PR #1001:
URL: https://github.com/apache/tomcat/pull/1001#discussion_r3751769684


##########
SECURITY.md:
##########
@@ -1,14 +1,136 @@
-# Security
+# Security Policy
 
-Apache Tomcat's security model and disclosure process are
-published on the project website rather than in the repository:
+## Before You Report - Required Self-Check
 
-- **Threat model and security policy**:
-  <https://tomcat.apache.org/security-model.html>
-- **How to report a vulnerability**: see the Security section
-  of <https://tomcat.apache.org/>.
+**Complete this checklist. If you answer "No" to any question, do not submit a report:**
 
-The project website is the authoritative source; this file
-exists so agents and tooling that look for `SECURITY.md` in
-the repository can mechanically follow the link to the
-canonical documents.
+- [ ] I have read the [Tomcat Security Model](https://tomcat.apache.org/security-model.html) and my finding doesn't require access to config files, binaries, or admin interfaces

Review Comment:
   Sounds good. I added "data stores" to both the self-check checklist and Security Model reference trusted list to cover the scenario mentioned.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.