I added an initial security policy in this PR
@samueleresca noted (❤️ ) in #25917 (comment) that it would be helpful to add additional documentation on how to harden DataFusion from threats by explicitly state the configurations that contribute to security hardening and their default.
For example, DuckDB does something similar in their operations manual.
Some corresponding examples in the DataFusion domain from @samueleresca:
He suggested
The stuff above might go in a dedicated section on the already existing Config page.
I would personally suggest adding a new page in our library user guide here:
I added an initial security policy in this PR
@samueleresca noted (❤️ ) in #25917 (comment) that it would be helpful to add additional documentation on how to harden DataFusion from threats by explicitly state the configurations that contribute to security hardening and their default.
For example, DuckDB does something similar in their operations manual.
Some corresponding examples in the DataFusion domain from @samueleresca:
SQLOptionsandwith_allow_ddl,with_allow_dml,with_allow_statementsare all allowed by default, as already mentioned.He suggested
I would personally suggest adding a new page in our library user guide here: