Skip to content

Conversation

@dill21yu
Copy link
Contributor

Purpose of the pull request

This pull request addresses issue #17472 by improving the project's security reporting documentation. Specifically:

Adds a SECURITY.md file in the repository root to override GitHub’s default ASF security policy page.
Updates the existing security documentation to use DolphinScheduler’s dedicated security email address ([email protected]) instead of the generic Apache one.
Includes a link to the official Apache Software Foundation Security Process as required.

Brief change log

Add SECURITY.md in the repository root with proper security reporting instructions.
Update docs/docs/en/contribute/join/security.md to reference the correct security email and ASF security process.
Synchronize the Chinese version: update docs/docs/zh/contribute/join/security.md accordingly.

Verify this pull request

This pull request is documentation-only and does not require code testing. It can be verified as follows:

Confirm that SECURITY.md appears on the GitHub Security Policy page.
Check that both English and Chinese security docs correctly list [email protected].
Validate that the ASF security process link (https://www.apache.org/security/committers.html) is present.

Pull Request Notice

Pull Request Notice

This change is fully compatible and does not introduce any breaking or incompatible changes. No update to incompatible.md is needed.

Copy link
Member

@SbloodyS SbloodyS left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please follow the pull request notice and use the correct title.

@@ -0,0 +1,41 @@
# Security
Copy link
Member

@SbloodyS SbloodyS Nov 24, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We don't need this file.

@dill21yu dill21yu changed the title docs: add SECURITY.md and update security contact (#17472) [Chore][Doc] Add SECURITY.md and update security contact (#17472) Nov 24, 2025
@dill21yu dill21yu requested a review from SbloodyS November 24, 2025 09:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants