From cd74f8af8e646118485569fb3ccadec6cf59d681 Mon Sep 17 00:00:00 2001 From: Andrew Lamb Date: Wed, 30 Sep 2026 15:35:01 -0400 Subject: [PATCH 1/2] Update SECURITY policy to conform to ASF rules Follow the ASF security reporting process (security@apache.org) instead of a personal email address, and document what is considered a security vulnerability vs. a bug, modeled on arrow-rs's SECURITY.md. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- SECURITY.md | 40 +++++++++++++++++++++++++++++++++++++++- 1 file changed, 39 insertions(+), 1 deletion(-) diff --git a/SECURITY.md b/SECURITY.md index 662ab74f0c..7e61a48138 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -19,6 +19,44 @@ # Security Policy +This document outlines the security model for `sqlparser-rs` and how to +report vulnerabilities. + +## Security Model + +`sqlparser-rs` parses SQL text, which is often untrusted input (e.g., a query +string from a user or an external system). The parser is expected to reject +invalid or malformed SQL with a normal error, without crashing or otherwise +behaving unexpectedly. + +Unexpected behavior (e.g., panics, crashes, excessive resource consumption, or +infinite loops) triggered by malformed or adversarial input is generally +considered a **bug**, not a security vulnerability, unless it is +**exploitable** and could allow an attacker to + +* Execute arbitrary code (Remote Code Execution); +* Exfiltrate sensitive information from process memory (Information Disclosure); + +If that exploitation path is unclear, the issue should likely be reported as a +bug. + +## Reporting a Bug + +We treat all bugs seriously and welcome help fixing them. If you find a bug +that does not meet the criteria for a security vulnerability, please report it +in the public issue tracker. + ## Reporting a Vulnerability -Please report security issues to `andrew@nerdnetworks.org` \ No newline at end of file +For security vulnerabilities, please follow the responsible disclosure process +below so we can investigate and fix the issue before it is exploited in the +wild. + +**Do not file a public issue.** Follow the [ASF security reporting process] by emailing [security@apache.org](mailto:security@apache.org). + +Include in your report: +- A clear description and minimal reproducer. +- Affected crates and versions. +- Potential impact. + +[ASF security reporting process]: https://www.apache.org/security/#reporting-a-vulnerability \ No newline at end of file From 55c3b7d86c15ff14e3ad5d490f721f4768b63ae1 Mon Sep 17 00:00:00 2001 From: Andrew Lamb Date: Wed, 30 Sep 2026 15:41:47 -0400 Subject: [PATCH 2/2] tweak --- SECURITY.md | 27 ++++++++++++--------------- 1 file changed, 12 insertions(+), 15 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 7e61a48138..c83785a1c2 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -25,20 +25,20 @@ report vulnerabilities. ## Security Model `sqlparser-rs` parses SQL text, which is often untrusted input (e.g., a query -string from a user or an external system). The parser is expected to reject -invalid or malformed SQL with a normal error, without crashing or otherwise -behaving unexpectedly. +string from a user or external system). The parser is expected to reject invalid +or malformed SQL with an error. -Unexpected behavior (e.g., panics, crashes, excessive resource consumption, or -infinite loops) triggered by malformed or adversarial input is generally -considered a **bug**, not a security vulnerability, unless it is -**exploitable** and could allow an attacker to +Unexpected behavior triggered by malformed or adversarial input is generally +considered a **bug**, not a security vulnerability, unless it is *exploitable** +and could allow an attacker to * Execute arbitrary code (Remote Code Execution); * Exfiltrate sensitive information from process memory (Information Disclosure); -If that exploitation path is unclear, the issue should likely be reported as a -bug. +For example, panics, crashes, stack overflows, excessive resource consumption, +or infinite loops are generally considered bugs, unless they can be exploited to +achieve one of the above security goals. If that exploitation path is unclear, +the issue should likely be reported as a bug. ## Reporting a Bug @@ -48,15 +48,12 @@ in the public issue tracker. ## Reporting a Vulnerability -For security vulnerabilities, please follow the responsible disclosure process -below so we can investigate and fix the issue before it is exploited in the -wild. - -**Do not file a public issue.** Follow the [ASF security reporting process] by emailing [security@apache.org](mailto:security@apache.org). +For security vulnerabilities, **do not file a public issue.** +Follow the [ASF security reporting process] by emailing [security@apache.org](mailto:security@apache.org). Include in your report: - A clear description and minimal reproducer. - Affected crates and versions. -- Potential impact. +- A demonstration of the potential impact. [ASF security reporting process]: https://www.apache.org/security/#reporting-a-vulnerability \ No newline at end of file