potiuk commented on PR #133:
URL: https://github.com/apache/solr-sandbox/pull/133#issuecomment-5133627702

   Makes sense — closing.
   
   Recording the reasoning here, since this PR is the only place the
   decision is written down: solr-sandbox was in the PMC's original
   four-repo scan scope (your list of 4 June), and this PR gave it the same
   discoverability wiring as the siblings. Your argument for dropping it —
   sandbox code isn't released by the PMC, carries no security or stability
   guarantee, and isn't meant for direct consumption — is exactly the kind
   of scope call a threat model should record rather than argue with. A
   scan report against it would land on you stripped of all that context.
   
   So solr-sandbox comes out of the scan scope, not just out of this PR.
   apache/solr is enrolled, apache/solr-operator joins it now that #841 has
   merged, and apache/solr-mcp joins when #160 merges.
   
   I've read "defer" as "out of scan scope" rather than "merge later" — say
   if you meant the latter and I'll reopen. Either way the draft stays in
   the branch history, so reviving it later is a five-minute job.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to