Add SECURITY.md per dev-list discussion - #1001
Conversation
|
Not crucial, but just a note from my point of view that it would be better to remove ❌ and 🔒 emojis in order to align with the tone of the rest of the docs. |
7d182c5 to
5ac9a78
Compare
|
I incorporated the changes from the brief SECURITY.md that was recently added into the proposal. I only made one small tweak to what I had already done since the current SECURITY.md topics are covered in this proposed change. |
|
How do you propose to address the conflicts? There looks to be some useful wording in the current file we should retain. I'm not sure about listing non-issues here and in the security model. I'd prefer not to duplicate. |
5ac9a78 to
a5a0506
Compare
|
I accidentally pushed a bad update, so I revisited this PR and think it's worth another look now. |
…uardrails for the tomcat project'
a5a0506 to
2c5d50f
Compare
|
I've resolved the feedback here and no updates in a week, so merging and will backport to 9.0.x also. |
…uardrails for the tomcat project' (#1001)
…uardrails for the tomcat project' (#1001)
…uardrails for the tomcat project' (#1001)
This change follows up on the dev-list discussion at https://lists.apache.org/thread/4mzg1hfp79tvjrk2mgw7oqx9ydwtd3l1 with a proposal for discussion.