Security
Security vulnerabilities in an openlakestream project are reported privately; this page states how, which releases get fixes, and what follows a report.
Please don't report security problems in a public issue, pull request or discussion.
Reporting a vulnerability
Report them privately, in either of these ways:
- GitHub private vulnerability reporting. Use the Report a vulnerability button on the Security tab of the affected repository, such as Ursa's or UFK's. This is the preferred channel: it's private, it keeps the conversation in one thread, and it stays attached to the repository.
- Email security@openlakestream.org, with the repository name in the subject line.
As much as you have of the following helps the maintainers act quickly:
- the affected version, image tag or commit
- what an attacker could do, and under which configuration
- steps to reproduce the problem
- anything you already know about the impact
A rough report sent early is better than a polished one sent late.
Vulnerabilities in Apache Kafka
Most of the Ursa for Apache Kafka (UFK) repository is Apache Kafka. If a problem also affects an Apache Kafka release, report it to the Apache Kafka security team, as described at kafka.apache.org/project-security. UFK picks up the fix when it syncs with Apache Kafka. If you're not sure which project a problem belongs to, report it privately as above, and the maintainers will work it out with you.
Supported versions
| Project | Receives security fixes |
|---|---|
| Ursa | The latest release line (currently 1.0.x) |
| UFK | The latest release |
Fixes land on the default branch and ship in the next release. Older releases don't receive patches, so upgrade to the latest release to pick up a fix.
What happens next
The maintainers acknowledge your report, investigate it, and keep you updated as they go. Disclosure is coordinated with you: by default the aim is to publish within 90 days of the report, and sooner once a fix is available. When the fix is released, a security advisory is published in the affected repository, crediting you unless you ask otherwise.
There is no bug bounty program.
Each repository's SECURITY.md is the authoritative policy for that repository.