Skip to content

[MINOR] Record PMC answers to the security THREAT_MODEL.md open questions#5275

Draft
jongyoul wants to merge 1 commit into
apache:masterfrom
jongyoul:threat-model-maintainer-answers
Draft

[MINOR] Record PMC answers to the security THREAT_MODEL.md open questions#5275
jongyoul wants to merge 1 commit into
apache:masterfrom
jongyoul:threat-model-maintainer-answers

Conversation

@jongyoul

Copy link
Copy Markdown
Member

Follow-up to #5268, which added the security THREAT_MODEL.md as a v0 draft for the PMC to review.

This folds the Apache Zeppelin PMC review answers into the document so it reflects maintainer positions rather than the draft (inferred) guesses:

  • Records the PMC answer for each open question in §14 (waves 1–3) inline.
  • Re-tags the corresponding (inferred) claims as (maintainer) across §2/§3/§5a/§6/§8/§9/§11a.
  • §5a: records the insecure-default ruling — anonymous-by-default, public notebooks, impersonation-off, and the shared binding mode are dev-conveniences / by-design, so reports against them are OUT-OF-MODEL: non-default-build.
  • §8: confirms authentication, notebook authorization (server-side), URL ACL (operator-configured), credential isolation, and impersonation confinement as committed properties; clarifies that resource/availability is not a committed property today (treated as VALID-HARDENING).
  • Keeps the core framing: RBAC is the trust boundary, not a sandbox.

Documentation only; no code changes.

…ions

Follow-up to apache#5268, which added THREAT_MODEL.md as a v0 draft for the PMC to review. This folds the Apache Zeppelin PMC review answers into the document: records the PMC answer for each open question in §14, and re-tags the corresponding (inferred) claims as (maintainer) across §2/§3/§5a/§6/§8/§9/§11a. Documentation only.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant