Lakestream
Community

Security

Security vulnerabilities in an openlakestream project are reported privately; this page states how, which releases get fixes, and what follows a report.

Please don't report security problems in a public issue, pull request or discussion.

Reporting a vulnerability

Report them privately, in either of these ways:

  1. GitHub private vulnerability reporting. Use the Report a vulnerability button on the Security tab of the affected repository, such as Ursa's or UFK's. This is the preferred channel: it's private, it keeps the conversation in one thread, and it stays attached to the repository.
  2. Email security@openlakestream.org, with the repository name in the subject line.

As much as you have of the following helps the maintainers act quickly:

  • the affected version, image tag or commit
  • what an attacker could do, and under which configuration
  • steps to reproduce the problem
  • anything you already know about the impact

A rough report sent early is better than a polished one sent late.

Vulnerabilities in Apache Kafka

Most of the Ursa for Apache Kafka (UFK) repository is Apache Kafka. If a problem also affects an Apache Kafka release, report it to the Apache Kafka security team, as described at kafka.apache.org/project-security. UFK picks up the fix when it syncs with Apache Kafka. If you're not sure which project a problem belongs to, report it privately as above, and the maintainers will work it out with you.

Supported versions

ProjectReceives security fixes
UrsaThe latest release line (currently 1.0.x)
UFKThe latest release

Fixes land on the default branch and ship in the next release. Older releases don't receive patches, so upgrade to the latest release to pick up a fix.

What happens next

The maintainers acknowledge your report, investigate it, and keep you updated as they go. Disclosure is coordinated with you: by default the aim is to publish within 90 days of the report, and sooner once a fix is available. When the fix is released, a security advisory is published in the affected repository, crediting you unless you ask otherwise.

There is no bug bounty program.

Each repository's SECURITY.md is the authoritative policy for that repository.