Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: simplify security list description

...

If your project handles many security reports, it can be helpful to introduce a private security@<project>.apache.org mailinglist. If such a list exists, security reports will be sent to this list instead of to the PMC, and we the ASF Security Team will no longer respond with a 'receipt confirmation' to the reporter - this is now your responsibility. The list should contain have enough PMC members to make sure the project can deal with any incoming messages about security issues responsibly and timely. You can also add trusted committers to this list, if they for some reason cannot or don't want to join the PMC.

How you as PMC invite and rotate the members of your security team is up to you to decide. For inspiration, you could have a look at how the Airflow PMC has arranged this. For example, it is encouraged to periodically rotate out participants from outside the PMC that are not actively contributing.

...