-
-
Notifications
You must be signed in to change notification settings - Fork 10.4k
security policy: take 1 #21119
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
security policy: take 1 #21119
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
This pull request significantly expands the project's security policy, adding important details on issue triage, severity levels, and a pre-notification process. The changes improve clarity for both users and contributors on how security issues are handled. My review focuses on ensuring the language in this formal document is clear, correct, and professional. I've pointed out a few grammatical and spelling issues that should be addressed to maintain the document's quality.
👋 Hi! Thank you for contributing to the vLLM project. 💬 Join our developer Slack at https://slack.vllm.ai to discuss your PR in #pr-reviews, coordinate on features in #feat- channels, or join special interest groups in #sig- channels. Just a reminder: PRs would not trigger full CI run by default. Instead, it would only run Once the PR is approved and ready to go, your PR reviewer(s) can run CI to test the changes comprehensively before merging. To run CI, PR reviewers can either: Add 🚀 |
minor thing - can you add |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
In general, this is great. I support the addition of the prenotification policy, allowing trusted parties that ship vllm to participate in a coordinated release. My suggestions are fairly minor, I think.
Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
Accept language change suggestions from gemini Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
Accept language change suggestions from gemini Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
Accept language change suggestions from gemini Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
Accept language change suggestions from gemini Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
Accept language change suggestions from gemini Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: Huzaifa Sidhpurwala <[email protected]>
867e24c
to
3652984
Compare
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: Russell Bryant <[email protected]>
One last suggestion - how about a link from https://docs.vllm.ai/en/latest/contributing/vulnerability_management.html back to SECURITY.md? You can find it in the |
Hmm, i can see already the following line in the vuln management page: Also, it seems like there may be a need to "consolidate" the vuln disclosure section of the page a bit, inline with the pre-notification policy. How about we commit the security policy first and then review how this page can be changed to be in sync with the policy? |
sounds good. I missed the link, sorry. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, but @simon-mo should review, as well.
Thanks!
@simon-mo hey, could you look at this MR and see if it makes sense to you? |
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: shuw <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: x22x22 <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: x22x22 <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: jingyu <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: Jinzhen Lin <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: Noam Gat <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: Paul Pak <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: Boyuan Feng <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]> Signed-off-by: Diego-Castan <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]>
Signed-off-by: Huzaifa Sidhpurwala <[email protected]> Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Co-authored-by: Russell Bryant <[email protected]>
Working on a new updated security policy for the project.
Most of the things were unsaid, like issue triage and security sevs, so documented them. Also added an initial version of a pre-notification policy.