Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The ASF encourages responsible disclosure of security vulnerabilities discovered in software managed by ASF projects.  The ASF security team sets a common policy, maintains security contacts for PMCs, and provides support for projects responding to security issues. Reporters are encouraged to use the designated security contacts to report vulnerabilities privately.  PMCs are required to respond to security reports promptly, working with reporters to investigate and if necessary develop patches.  

The ASF Security team are is a CVE Project Candidate Naming Authority (CNA). CVE names are issued to vulnerabilities regardless if they are found by the project committers, members, PMCs, other ASF members, or third-parties.  The ASF Security team and PMCs work from time to time with third parties who wish to perform security functions such as code audits, bug bounties.  

...