Skip to content

Add AGENTS.md + SECURITY.md pointing to the security model (scanner discoverability)#1932

Merged
rzo1 merged 1 commit into
apache:mainfrom
potiuk:asf-security/discoverability-2026-06-05
Jun 5, 2026
Merged

Add AGENTS.md + SECURITY.md pointing to the security model (scanner discoverability)#1932
rzo1 merged 1 commit into
apache:mainfrom
potiuk:asf-security/discoverability-2026-06-05

Conversation

@potiuk
Copy link
Copy Markdown
Member

@potiuk potiuk commented Jun 5, 2026

Adds an AGENTS.md and SECURITY.md at the repo root, both pointing to the existing Apache StormCrawler Security Model, so automated security scanners (and researchers) can mechanically discover the project's threat model via the standard AGENTS.md -> SECURITY.md -> model chain.

Also adds AGENTS.md and SECURITY.md to the apache-rat-plugin excludes in pom.xml, matching the existing treatment of CONTRIBUTING.md / RELEASING.md.

No code or behaviour changes — documentation/metadata only. This is a proposal for the PMC to review; please adjust or reject as needed.

@rzo1 rzo1 merged commit 14eca05 into apache:main Jun 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants