Hi Stamatis, Thanx for starting the thread. I am +1 to the proposal, adding the reviewer also makes sense to me
-Ayush On Fri, 25 Sept 2026 at 10:29, Shohei Okumiya <[email protected]> wrote: > > Hi Stamatis, > > Thanks for investigating the patterns. I agree with your proposal; > it's the best approach for our project. > > Best, > Okumin > > On Thu, Sep 24, 2026 at 5:05 PM Stamatis Zampetakis <[email protected]> > wrote: > > > > There have been some side questions on how to provide credits for > > these findings coming through the Glasswing scan and deserve a CVE > > publication. I took a quick look in the [email protected] where CVEs > > are published and found the following patterns used by other ASF > > projects. > > > > ## Apache Sling > > > > The Apache Software Foundation (finder) > > Claude Code (tool) > > > > ## Apache Airflow > > > > Claude Security Scans (tool) > > Jarek Potiuk (remediation developer) > > > > ## Apache Neethi > > > > This issue was found using Claude agents to study the security of > > open-source projects (finder) > > > > ## Apache Storm > > > > The ASF using Claude Agents (finder) > > > > Personally, the one I like the most is the Airflow pattern. I would > > propose to use that with a small addition to acknowledge the reviewer. > > > > ## Apache Hive > > > > Claude Security Scans (tool) > > Stamatis Zampetakis (remediation developer) > > Alice Hacker (remediation reviewer) > > > > Best, > > Stamatis > > > > On Wed, Sep 9, 2026 at 10:20 AM Stamatis Zampetakis <[email protected]> > > wrote: > > > > > > Hi all, > > > > > > Various ASF projects including Hive are using AI to find security > > > vulnerabilities and harden security. This topic was confidential till now > > > so we were not allowed to publicly talk about what is happening behind > > > the scenes. From now on, the news is public and you can read all details > > > in the official ASF blog post [1]. > > > > > > The Glasswing scan for Hive was delivered in [email protected] and > > > the team is actively working on triaging and fixing the reported issues. > > > Hive PMC and committers can (and are strongly encouraged to) subscribe to > > > the security mailing list (using their @apache.org address) to follow the > > > progress and help out in this initiative. > > > > > > Best, > > > Stamatis > > > > > > [1] > > > https://news.apache.org/foundation/entry/security-scanning-at-foundation-scale
