Hi Stamatis, Thanks for investigating the patterns. I agree with your proposal; it's the best approach for our project.
Best, Okumin On Thu, Sep 24, 2026 at 5:05 PM Stamatis Zampetakis <[email protected]> wrote: > > There have been some side questions on how to provide credits for > these findings coming through the Glasswing scan and deserve a CVE > publication. I took a quick look in the [email protected] where CVEs > are published and found the following patterns used by other ASF > projects. > > ## Apache Sling > > The Apache Software Foundation (finder) > Claude Code (tool) > > ## Apache Airflow > > Claude Security Scans (tool) > Jarek Potiuk (remediation developer) > > ## Apache Neethi > > This issue was found using Claude agents to study the security of > open-source projects (finder) > > ## Apache Storm > > The ASF using Claude Agents (finder) > > Personally, the one I like the most is the Airflow pattern. I would > propose to use that with a small addition to acknowledge the reviewer. > > ## Apache Hive > > Claude Security Scans (tool) > Stamatis Zampetakis (remediation developer) > Alice Hacker (remediation reviewer) > > Best, > Stamatis > > On Wed, Sep 9, 2026 at 10:20 AM Stamatis Zampetakis <[email protected]> > wrote: > > > > Hi all, > > > > Various ASF projects including Hive are using AI to find security > > vulnerabilities and harden security. This topic was confidential till now > > so we were not allowed to publicly talk about what is happening behind the > > scenes. From now on, the news is public and you can read all details in the > > official ASF blog post [1]. > > > > The Glasswing scan for Hive was delivered in [email protected] and > > the team is actively working on triaging and fixing the reported issues. > > Hive PMC and committers can (and are strongly encouraged to) subscribe to > > the security mailing list (using their @apache.org address) to follow the > > progress and help out in this initiative. > > > > Best, > > Stamatis > > > > [1] > > https://news.apache.org/foundation/entry/security-scanning-at-foundation-scale
