Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-9619

Remove GPG key from Security Disclosure details

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Trivial
    • Resolution: Fixed
    • None
    • 1.16.0
    • None

    Description

      The Security Vulnerability Disclosure instructions reference a GPG key fingerprint for security@nifi.apache.org as an option for reporting sensitive information. The public key associated with the fingerprint expired on 2021-03-23. The difficulty of sharing a GPG private key with all members of the PMC outweighs the potential benefit of supporting this method of vulnerability reporting. For these reasons, the GPG key fingerprint should be removed from the Security Vulnerability Disclosure instructions.

      Attachments

        Activity

          People

            exceptionfactory David Handermann
            exceptionfactory David Handermann
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 1h 10m
                1h 10m