Skip to content

docs: clarify security guidance#2961

Open
He-Pin wants to merge 1 commit into
apache:mainfrom
He-Pin:port-fe097c3-security-announcements
Open

docs: clarify security guidance#2961
He-Pin wants to merge 1 commit into
apache:mainfrom
He-Pin:port-fe097c3-security-announcements

Conversation

@He-Pin
Copy link
Copy Markdown
Member

@He-Pin He-Pin commented May 9, 2026

No description provided.

@He-Pin He-Pin marked this pull request as ready for review May 9, 2026 18:48
Motivation:
The security announcements page should use Apache Pekko-specific reporting guidance and keep readers on the Apache Pekko security announcements page for project security information.

Modification:
Clarify that issues affecting Apache Pekko and its predecessor project should be reported to the Apache Pekko team first, describe responsible disclosure coordination with affected upstream maintainers, and update the security-related documentation link to the Apache Pekko security announcements page.

Result:
The security documentation now avoids predecessor project branding in authored text, links to the Apache Pekko security announcements page, and better matches the Apache Pekko reporting process.

Tests:
- git diff --check / passed
- sbt docs/paradox / passed with existing duplicate-anchor warnings in release notes only

References:
Upstream commit: akka/akka-core@fe097c3, which is now Apache licensed
Refs #31927

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@He-Pin He-Pin force-pushed the port-fe097c3-security-announcements branch from be5ce49 to eccad3b Compare May 9, 2026 18:57

Ideally, any issues affecting Apache Pekko and Akka should be reported to Apache team first. We will share the
report with the Lightbend Akka team.
Ideally, any issues affecting Apache Pekko and its predecessor project should be reported to the Apache Pekko team
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't see why we shouldn't name Akka here.

@He-Pin He-Pin requested a review from pjfanning May 9, 2026 20:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants