*** Unsent and unapproved draft ***

How the ASF keeps our projects secure

(add 3-4 bullet points about our controls and processes here and how they help, lead to these as recommended practices)

About the recent issues in log4j

Before jumping directly into recommendations, it is worth describing the factors contributing to the recent log4j vulnerability.  Our recommendations are based on those experiences as well as over 20 years of dealing with vulnerabilities in open source software.

Recommendations

These experiences inform our positions on a number of items.