Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
37 changes: 36 additions & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,41 @@

# Security Policy

This document outlines the security model for `sqlparser-rs` and how to
report vulnerabilities.

## Security Model

`sqlparser-rs` parses SQL text, which is often untrusted input (e.g., a query
string from a user or external system). The parser is expected to reject invalid
or malformed SQL with an error.

Unexpected behavior triggered by malformed or adversarial input is generally

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This very much follows the arrow-rs model -- I am not sure we need to expand the scope for SQLParser but am open to suggestions

considered a **bug**, not a security vulnerability, unless it is *exploitable**
and could allow an attacker to

* Execute arbitrary code (Remote Code Execution);
* Exfiltrate sensitive information from process memory (Information Disclosure);

For example, panics, crashes, stack overflows, excessive resource consumption,
or infinite loops are generally considered bugs, unless they can be exploited to
achieve one of the above security goals. If that exploitation path is unclear,
the issue should likely be reported as a bug.

## Reporting a Bug

We treat all bugs seriously and welcome help fixing them. If you find a bug
that does not meet the criteria for a security vulnerability, please report it
in the public issue tracker.

## Reporting a Vulnerability

Please report security issues to `andrew@nerdnetworks.org`
For security vulnerabilities, **do not file a public issue.**
Follow the [ASF security reporting process] by emailing [security@apache.org](mailto:security@apache.org).

Include in your report:
- A clear description and minimal reproducer.
- Affected crates and versions.
- A demonstration of the potential impact.

[ASF security reporting process]: https://www.apache.org/security/#reporting-a-vulnerability
Loading