Skip to content

Update SECURITY policy to conform to ASF guidelines - #2601

Merged
LucaCappelletti94 merged 2 commits into
apache:mainfrom
alamb:update-security-policy
Oct 1, 2026
Merged

LucaCappelletti94 merged 2 commits into
apache:mainfrom
alamb:update-security-policy

Conversation

@alamb

@alamb alamb commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

What's not working

Our SECURITY.md lists my personal email as the security contact and doesn't follow ASF guidelines or explain what counts as a security vulnerability vs. a regular bug.

Fix

Update SECURITY.md, modeled on arrow-rs's SECURITY.md: https://github.com/apache/arrow-rs/blob/main/SECURITY.md

alamb and others added 2 commits September 30, 2026 15:35
Follow the ASF security reporting process (security@apache.org) instead
of a personal email address, and document what is considered a security
vulnerability vs. a bug, modeled on arrow-rs's SECURITY.md.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@alamb
alamb marked this pull request as ready for review September 30, 2026 19:42
@alamb alamb changed the title Update SECURITY policy to conform to ASF rules Update SECURITY policy to conform to ASF guidelines Sep 30, 2026
Comment thread SECURITY.md
string from a user or external system). The parser is expected to reject invalid
or malformed SQL with an error.

Unexpected behavior triggered by malformed or adversarial input is generally

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This very much follows the arrow-rs model -- I am not sure we need to expand the scope for SQLParser but am open to suggestions

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.09%. Comparing base (5cad906) to head (55c3b7d).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #2601   +/-   ##
=======================================
  Coverage   81.09%   81.09%           
=======================================
  Files          42       42           
  Lines       33684    33684           
  Branches    33684    33684           
=======================================
  Hits        27316    27316           
  Misses       2798     2798           
  Partials     3570     3570           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@LucaCappelletti94

Copy link
Copy Markdown
Contributor

@alamb merging

@LucaCappelletti94
LucaCappelletti94 added this pull request to the merge queue Oct 1, 2026
Merged via the queue into apache:main with commit 811ef29 Oct 1, 2026
15 checks passed
@alamb

alamb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Nice -- thanks @LucaCappelletti94

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update SECURITY policy to conform to ASF rules

4 participants