Skip to content

[#] SECURITY.md updates#2034

Merged
cshannon merged 5 commits into
apache:mainfrom
mattrpav:amq-gh-2006-security-part2
May 22, 2026
Merged

[#] SECURITY.md updates#2034
cshannon merged 5 commits into
apache:mainfrom
mattrpav:amq-gh-2006-security-part2

Conversation

@mattrpav
Copy link
Copy Markdown
Contributor

No description provided.

@mattrpav mattrpav self-assigned this May 21, 2026
@mattrpav mattrpav requested review from cshannon and jbonofre May 21, 2026 14:05
jbonofre
jbonofre previously approved these changes May 21, 2026
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
@cshannon
Copy link
Copy Markdown
Contributor

@mattrpav - I think one more comment to add to the new section is to mention that we don't consider vulnerability reports that require no authentication or authorization to be valid. We constantly get reports with "out of the box" defaults meant for developers. While we are changing that, it's still good to point out that if a security issue requires authentication to be turned off then that is not valid because there should be no expectation of protection if a user doesn't turn on proper authentication and authorization controls.

@cshannon
Copy link
Copy Markdown
Contributor

I'm going to go ahead and merge what we have for now and we can make more updates going forward as i'm sure there will be plenty more changes as we go.

@cshannon cshannon merged commit 1ae2832 into apache:main May 22, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants