Skip to content

docs(security): add reporter-unresponsiveness escalation per ASF policy to security-issue-sync - #1073

Draft
harishkesavarao wants to merge 1 commit into
apache:mainfrom
harishkesavarao:security-issue-sync/reporter-unresponsive-escalation
Draft

docs(security): add reporter-unresponsiveness escalation per ASF policy to security-issue-sync#1073
harishkesavarao wants to merge 1 commit into
apache:mainfrom
harishkesavarao:security-issue-sync/reporter-unresponsive-escalation

Conversation

@harishkesavarao

Copy link
Copy Markdown

Summary

Implements ASF security-committers policy: reporter unresponsiveness must not block the process.

  • skills/security-issue-sync/gather.md: Step 1c now checks staleness. If the team's last message to the reporter is older than a configurable threshold with no reply since, the thread is flagged for Step 2b.
  • skills/security-issue-sync/signals-to-actions.md: new proposal category emits the numbered item "Reporter has not replied in N days, propose proceeding with fix and announcement without further reporter sign-off, per ASF policy." Proposal only, never auto-applied. Reappears each sync pass while still stale.
  • projects/_template/project.md: added reporter_response_timeout_days config key, default 14, under Security inbox.
  • docs/security/process.md: note after Step 4 separating team-discussion stalls from reporter unresponsiveness, with a link to the policy and the config key.
  • docs/security/roles.md: note in "Keeping the reporter informed" stating a silent reporter doesn't block progress, pointing to the same config key.

Ran skill-and-tool-validator. No new failures, only pre-existing warnings.

Type of change

  • Skill change (.claude/skills/<name>/) — eval fixtures updated below
  • Tool / bridge contract (tools/<system>/*.md)
  • Python package (tools/*/ with pyproject.toml)
  • Groovy reference impl
  • Cross-cutting (RFC, AGENTS.md, sandbox, privacy-LLM)
  • Documentation (docs/, README.md, CONTRIBUTING.md)
  • Project template (projects/_template/)
  • CI / dev loop (prek, workflows, validators)
  • Other:

Test plan

  • prek run --all-files passes
  • For Python packages touched: uv run pytest / ruff check / mypy passes
  • For Groovy bridges touched: command-line invocation tested end-to-end
  • For skill changes: eval suite passes for the affected skill
    (PYTHONPATH=tools/skill-evals/src python3 -m skill_evals.runner tools/skill-evals/evals/<skill>/)
  • For skill behaviour changes: a new or updated eval fixture is included in this PR
    (a regression test for the bug fixed / the behaviour added — see CONTRIBUTING.md)
  • Other:

RFC-AI-0004 compliance

  • HITL — any new mutation is gated on explicit user confirmation
  • Sandbox — no new unrestricted host access; network reach declared in the adapter
  • Vendor neutrality — placeholders (<PROJECT>, <tracker>, <upstream>, <security-list>) used in all skill / tool prose (the check-placeholders prek hook is the mechanical gate)
  • Conversational + correctable — agentic-override path documented if behaviour is adopter-tunable
  • Write-access discipline — no autonomous outbound messages; drafts only, sent on confirmation
  • Privacy LLM — private content does not reach a non-approved LLM; redactor invoked where needed

Linked issues

Notes for reviewers (optional)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant