docs: Add SECURITY.md for Apache Lucene - #16585
Conversation
dweiss
left a comment
There was a problem hiding this comment.
LGTM. There seems to be one sentence where the syntax I don't fully comprehend... I added a suggestion which I think makes it clearer but I don't pretend to be as fluent in English as Claude. ;)
Co-authored-by: Dawid Weiss <dawid.weiss@gmail.com>
|
I applied Dawid's small change, but I am not sure if this is well written. Maybe an English speaker should comment. |
I reverted that again. Looks like the "it" is required, ClaudeSays™:
I have committed a better readable sentence which reads smoother:
So it is your idea, just in correct order. |
e607417 to
973af1e
Compare
I understand the explanation. I also swear I read the sentence 10 times and couldn't get the meaning of it... :) |
|
I added another sentence that we do not have a bug bounty program (because this is always requested in reports. The sentence was copied from ASF pages. |
…o dev/security-info
|
"the application embedding it" ~~ "the application in which it is embedded" is how I was finally able to parse it |
I don't undertstand that comment, Should I change it or is the current text ok? It is obvious if you read the previous sentence. |
Yes it's fine, sorry to confuse the issue. I was just suggesting a possible alternative, that to me, is clearer. But either way is fine. |
The sentence before has "downstream application" in its description, I could replace "embedding application" by "downstream application". This would not change structure of sentence (I don't like yours its harder for me to read). What do you think? I am planning to merge this tomorrow (after 72 hours) to allow others to review. After that I will proceed with open security issues and comment to reporter with a reference to this file. Actually at moment there is only one open one which is long overdue, so this is why I want to hurry up. |
Yes maybe that's better? I think the word "embedding" has gotten somewhat hijacked by vector embeddings in my mind anyway. |
|
I cherry picked this into 10.x branch so we have the new file also in source code of new releases. |
As the number of reported security issues also went up - and many of them were rejected, I used some time to create a
SECURITY.mdfile with some basic instructions how to report security issues.I am not sure if we should also add this to our web page, I'd like to start with the Git repo.
The text was mocked by Claude Fable 5 (Claude Max provided for ASF committers) and I rewrote + corrected it significantly. I tried to not add too much "UweSays style" texts :-)
I am free to discuss this, possibly again at Community over Code in October. But as mentioned already on the private list, I want to give it a go soon.