potiuk opened a new pull request, #45: URL: https://github.com/apache/tooling-agents/pull/45
Adds a security-team **processing report** for the three opus-4.8 (Opus 4.8 + audit-guidance) ASVS scans of Apache Airflow, under `ASVS/reports/opus-4.8/airflow/`. It's a cross-scan overview that complements the per-finding triage already posted on the source issues — #23 (airflow-core), #24 (task-sdk), #34 (providers/google): - per-scan outcomes — **41 findings → 2 hardening PRs, 0 CVEs, 0 new trackers**; - disposition breakdown with percentages; - severity-vs-reality analysis — 6 Medium findings, **0 surviving as vulnerabilities** after a code-level trust-boundary triage; - an assessment of what the scanner is and isn't good for (a defense-in-depth / hygiene coverage checklist rather than a threat-model-aware vulnerability finder), including a note that the opus-4.8 + audit-guidance round is markedly cleaner than earlier rounds. Docs-only — one new markdown file. ##### Was generative AI tooling used to co-author this PR? - [X] Yes — Claude Opus 4.8 (1M context) Generated-by: Claude Opus 4.8 (1M context) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
