Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tell users what to do if their scanners find issues in the image #37652

Commits on Feb 23, 2024

  1. Tell users what to do if their scanners find issues in the image

    We often get reports with results of the image scanning sent to
    the security team. However, for 3rd-party CVEs which are public,
    this is wrong way of reporting them and our users have other ways
    they can either handle it, or research it or contribute back their
    findings back and it's not clear for them that a) they have those
    options b) their expectations are that Airflow security team will
    tell them how to clear their security scan reports, c) they do not
    know they should (and can) contribute back.
    
    This change restructures and clarifies the chapter that was describing
    it in a pretty vague way - turning it into "How to" guide for the
    users, explaining all the options they have and explaining what are
    the ways they can contribute back - also making it crystal clear
    what is the responsibility of the security team for it and that
    the community expects contributions in such cases from commercial
    users who want their security reports cleared, not the other way
    round.
    potiuk committed Feb 23, 2024
    Configuration menu
    Copy the full SHA
    4532a8f View commit details
    Browse the repository at this point in the history