Add SECURITY.md for DataFusion - #25917
Conversation
Closes apache#25916 Adds a security policy modeled on arrow-rs's SECURITY.md (https://github.com/apache/arrow-rs/blob/main/SECURITY.md), describing the security model and pointing reporters to the ASF security reporting process (https://www.apache.org/security/#reporting-a-vulnerability). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
| //! Substrait does not (yet) support the full range of plans and expressions | ||
| //! that DataFusion offers. See the [datafusion-proto] crate for a DataFusion | ||
| //! specific format that does support of the full range. | ||
| //! that DataFusion offers. See the [datafusion-proto] crate for a DataFusion |
| //! # use datafusion_proto::bytes::Serializeable; | ||
| //! # fn main() -> Result<()>{ | ||
| //! // Create a new `Expr` a < 32 | ||
| //! // Create a new `Expr` a < 5 |
| under the License. | ||
| --> | ||
|
|
||
| # Security Policy |
There was a problem hiding this comment.
The goal of this file is to write down what I think have been implicit assumptions. But since they haven't been written down, I am not sure if everyone has the same assumptions
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #25917 +/- ##
==========================================
- Coverage 82.69% 82.68% -0.01%
==========================================
Files 1147 1147
Lines 447204 447204
Branches 447204 447204
==========================================
- Hits 369793 369782 -11
- Misses 55002 55010 +8
- Partials 22409 22412 +3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
phillipleblanc
left a comment
There was a problem hiding this comment.
Looks good to me, thanks Andrew!
martin-g
left a comment
There was a problem hiding this comment.
https://github.com/apache/datafusion/security/policy also states a Security Policy.
It looks like it loads its contents from .github/SECURITY.md but there is no such at https://github.com/apache/datafusion/tree/main/.github
I guess it inherited from https://github.com/apache org.
Maybe we should symlink this file to .github/SECURITY.md ?!
Co-authored-by: Martin Grigorov <martin-g@users.noreply.github.com>
I agree if https://github.com/apache/datafusion/security/policy doesn't automatically update when we merge this PR in |
|
I'll plan to merge this on Monday Oct 5 unless anyone else would like time to review |
|
Overall, looks good. A minor note. My preference would be to explicitly state the configurations that contribute to security hardening and their default. For example, DuckDB does something similar. Some corresponding examples in the DataFusion domain:
The stuff above might go in a dedicated section on the already existing Config page. Other notes:
|
Thank you @samueleresca - That is a good idea-- however I don't think it belongs in the security policy which should be the general purpose guidelines and policy. Indeed the doc you linked from DuckDB is actually an "operations manual" -- similar in spirit to our "library user's guide" I will file a follow on issue to track adding such as "securing DataFusion" section Update: filed |
I think this is obvious, so I don't think it is worth a specific note here. |
Yes this is a great idea. Added in 4598b30. Thank you @samueleresca |
|
Thank you everyone, I will merge this one and then we can iterate on it after that |
https://github.com/apache/datafusion/security/policy is updated! Nothing else to do! |
Which issue does this PR close?
Rationale for this change
As an ASF project, DataFusion should follow the ASF reporting guidelines and provide a means for responsible security disclosures.
What changes are included in this PR?
Adds a top-level
SECURITY.mdmodeled on arrow-rs's SECURITY.md (and a similar update made in apache/datafusion-sqlparser-rs#2601). It describes:It also adopts several ideas from DuckDB's excellent security policy. 🎩 🙏
What is the testing strategy for this PR?
CI
Are there any user-facing changes?
Adds a new
SECURITY.mdfile at the repository root, visible on GitHub's repository page under 'Security'.