Skip to content

Add SECURITY.md for DataFusion - #25917

Merged
alamb merged 11 commits into
apache:mainfrom
alamb:security-policy
Oct 5, 2026
Merged

alamb merged 11 commits into
apache:mainfrom
alamb:security-policy

Conversation

@alamb

@alamb alamb commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Which issue does this PR close?

Rationale for this change

As an ASF project, DataFusion should follow the ASF reporting guidelines and provide a means for responsible security disclosures.

What changes are included in this PR?

Adds a top-level SECURITY.md modeled on arrow-rs's SECURITY.md (and a similar update made in apache/datafusion-sqlparser-rs#2601). It describes:

  • The security model for DataFusion (what counts as a bug vs. a vulnerability)
  • How to report ordinary bugs (public issue tracker)
  • How to report vulnerabilities

It also adopts several ideas from DuckDB's excellent security policy. 🎩 🙏

What is the testing strategy for this PR?

CI

Are there any user-facing changes?

Adds a new SECURITY.md file at the repository root, visible on GitHub's repository page under 'Security'.

alamb and others added 2 commits September 30, 2026 15:57
Closes apache#25916

Adds a security policy modeled on arrow-rs's SECURITY.md
(https://github.com/apache/arrow-rs/blob/main/SECURITY.md), describing
the security model and pointing reporters to the ASF security
reporting process (https://www.apache.org/security/#reporting-a-vulnerability).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@alamb alamb changed the title Add SECURITY.md following ASF guidelines Add SECURITY.md Security Policy Sep 30, 2026
@alamb alamb added the documentation Improvements or additions to documentation label Sep 30, 2026
@github-actions github-actions Bot added substrait Changes to the substrait crate proto Related to proto crate and removed documentation Improvements or additions to documentation labels Sep 30, 2026
//! Substrait does not (yet) support the full range of plans and expressions
//! that DataFusion offers. See the [datafusion-proto] crate for a DataFusion
//! specific format that does support of the full range.
//! that DataFusion offers. See the [datafusion-proto] crate for a DataFusion

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

drive by cleanup

//! # use datafusion_proto::bytes::Serializeable;
//! # fn main() -> Result<()>{
//! // Create a new `Expr` a < 32
//! // Create a new `Expr` a < 5

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

drive by

Comment thread SECURITY.md
under the License.
-->

# Security Policy

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The goal of this file is to write down what I think have been implicit assumptions. But since they haven't been written down, I am not sure if everyone has the same assumptions

@alamb alamb changed the title Add SECURITY.md Security Policy Add SECURITY.md for DataFusion Sep 30, 2026
@alamb
alamb marked this pull request as ready for review September 30, 2026 20:56
@codecov-commenter

codecov-commenter commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 82.68%. Comparing base (bd86190) to head (4598b30).

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #25917      +/-   ##
==========================================
- Coverage   82.69%   82.68%   -0.01%     
==========================================
  Files        1147     1147              
  Lines      447204   447204              
  Branches   447204   447204              
==========================================
- Hits       369793   369782      -11     
- Misses      55002    55010       +8     
- Partials    22409    22412       +3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@phillipleblanc phillipleblanc left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me, thanks Andrew!

@martin-g martin-g left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

https://github.com/apache/datafusion/security/policy also states a Security Policy.
It looks like it loads its contents from .github/SECURITY.md but there is no such at https://github.com/apache/datafusion/tree/main/.github
I guess it inherited from https://github.com/apache org.
Maybe we should symlink this file to .github/SECURITY.md ?!

Comment thread SECURITY.md Outdated
@alamb alamb added the documentation Improvements or additions to documentation label Oct 1, 2026
Co-authored-by: Martin Grigorov <martin-g@users.noreply.github.com>
@github-actions github-actions Bot removed the documentation Improvements or additions to documentation label Oct 1, 2026
@alamb

alamb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Maybe we should symlink this file to .github/SECURITY.md ?

I agree if https://github.com/apache/datafusion/security/policy doesn't automatically update when we merge this PR in

@jayzhan211 jayzhan211 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍🏻

@alamb

alamb commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

I'll plan to merge this on Monday Oct 5 unless anyone else would like time to review

@samueleresca

Copy link
Copy Markdown
Member

Overall, looks good.

A minor note. My preference would be to explicitly state the configurations that contribute to security hardening and their default. For example, DuckDB does something similar. Some corresponding examples in the DataFusion domain:

The stuff above might go in a dedicated section on the already existing Config page.

Other notes:

  • Worth stating that DataFusion relies on other OSS dependencies, and security reports affecting downstream dependencies should be opened in the corresponding repos?
  • Should the model state explicitly whether datafusion-cli is included or not in the model?

@comphead comphead left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good start, thanks @alamb

@alamb

alamb commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor Author

A minor note. My preference would be to explicitly state the configurations that contribute to security hardening and their default. For example, DuckDB does something similar. Some corresponding examples in the DataFusion domain:

Thank you @samueleresca - That is a good idea-- however I don't think it belongs in the security policy which should be the general purpose guidelines and policy. Indeed the doc you linked from DuckDB is actually an "operations manual" -- similar in spirit to our "library user's guide"

I will file a follow on issue to track adding such as "securing DataFusion" section

Update: filed

@alamb

alamb commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author
  • Worth stating that DataFusion relies on other OSS dependencies, and security reports affecting downstream dependencies should be opened in the corresponding repos?

I think this is obvious, so I don't think it is worth a specific note here.

@alamb

alamb commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Should the model state explicitly whether datafusion-cli is included or not in the model?

Yes this is a great idea. Added in 4598b30. Thank you @samueleresca

@alamb

alamb commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Thank you everyone, I will merge this one and then we can iterate on it after that

@alamb
alamb added this pull request to the merge queue Oct 5, 2026
Merged via the queue into apache:main with commit b40d696 Oct 5, 2026
42 checks passed
@alamb
alamb deleted the security-policy branch October 5, 2026 22:33
@martin-g

martin-g commented Oct 6, 2026

Copy link
Copy Markdown
Member

I agree if https://github.com/apache/datafusion/security/policy doesn't automatically update when we merge this PR in

https://github.com/apache/datafusion/security/policy is updated! Nothing else to do!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

proto Related to proto crate substrait Changes to the substrait crate v56.0.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a security policy

9 participants