(Adapted from Apache Spark and Apache Kafka)
To report a security vulnerability in Apache SystemDS, follow the ASF security process. Please do not open public GitHub issues, create public pull requests, file public JIRA tickets, or post to mailing lists for unpatched vulnerabilities. Reports can be sent privately to security@apache.org.
The Apache SystemDS security model is documented under site/security.