potiuk opened a new pull request, #910:
URL: https://github.com/apache/ws-axiom/pull/910

   **This is a proposal for the PMC to review — please correct, reject, or
   discuss as needed.** Nothing here is a requirement; the maintainer is the
   decision-maker.
   
   This wires up the security model that already landed in this repo
   (`THREAT-MODEL.md`) so an automated scan agent can discover it
   mechanically, via the conventional `AGENTS.md` → `SECURITY.md` → model
   chain. It adds no model content and changes none of the existing text.
   
   Context: the ASF Security team is preparing this project for an automated
   agentic security scan we're piloting. Such scans refuse to run when the
   model isn't reachable by that path — refusing upfront beats spending PMC
   reviewer cycles on a noise-heavy run against a model the agent never
   found. Discoverability is the one hard gate; everything else is
   suggestion.
   
   This is a follow-up to the threat-model PR already merged here: that one
   added the document, but not the small pointer files the scan agent needs
   to *find* it. That omission was ours, not the PMC's.
   
   Questions or pushback welcome — happy to adjust wording or file placement
   to match the project's house style.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to