Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: minor wording tweak

...

Nonetheless, the PMC can ask for help in handling security issues: if the PMC does not have the bandwidth to handle issues within a reasonable time, or if they want to ask the help of a trusted community member or outside subject matter expert, they can share information about the report in private on a one-on-one need-to-know basis. As with all communication around security issues, it is recommended to Cc security@apache.org in the exchange. Of course, it should be clear that you expect them to keep the shared information private.

...

If your project handles many security reports, it can be helpful to introduce a private security@<project>.apache.org mailinglist. If such a list exists, security reports will be sent to this list instead of to the PMC. The list should contain enough PMC members to make sure the project can responsibly deal with any incoming security reports. You can also add trusted committers to this list, who if they for some reason cannot or don't want to join the PMC.

...