lukaszlenart opened a new pull request, #1917: URL: https://github.com/apache/struts/pull/1917
Both security skills stated that a CVE is requested only after the fixed release is out, phrased as a hard constraint. It is a PMC practice (a silent consensus from earlier discussions), not an ASF rule — the ASF committer security process permits allocating a CVE earlier and sharing the id with the reporter. ## Changes - `triaging-security-reports/SKILL.md` — reword the CVE guidance from "requested once the fixed release is out, never at triage" to our-practice / PMC's-call framing, noting ASF permits earlier allocation. - `creating-security-bulletins/SKILL.md` — same reframe on the CVE placeholder section. - Soften the matching red-flag and common-mistake lines to say CVE *timing* is a PMC choice, not a fixed rule. The operational guidance is preserved: a triage reply must still not commit the project to a CVE or its timing. Docs-only change under `.claude/` — no Jira ticket, conventional-commit form per `CLAUDE.md`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
