---
title: "Security Policy"
description: "Learn how to report security issues to us."
source: https://cloudberry.apache.org/community/security
---

# Apache Cloudberry Security

The Apache Security Team handles all security issues across Apache projects and
coordinates the response to vulnerabilities. For details on the vulnerability
handling process, supported versions, and what is considered a security issue,
visit: https://www.apache.org/security/.

## Do not

For better collaboration, we hope you:

- DO NOT report non-security-impacting bugs through this channel. If you have
  any questions on using, development, please use [GitHub
  Issues](https://github.com/apache/cloudberry/issues),
  [Discussions](https://github.com/apache/cloudberry/discussions), [Dev mailing
  list](/community/mailing-lists) or
  [Slack](https://join.slack.com/t/asf-cloudberry/shared_invite/zt-3um34r7hf-Sh~6jG6hVxlQJo1tbhK2sw) instead.
- DO NOT report security issues on public GitHub Issues, Jira tickets, mailing
  lists, or other public forums.

## Reporting Security Issues

Send your report to: [security@apache.org](mailto:security@apache.org).

Please send one plain-text email per vulnerability with the following and
additional information as necessary (as much as you can provide):

- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Potential impact
- Any known mitigations
- (Optional) Suggested fix

## Public Discussion

For general security questions or discussions, please use the development
mailing list: [dev@cloudberry.apache.org](mailto:dev@cloudberry.apache.org)

## Preferred Languages

We prefer all communications to be in English.
