Skip to content

Add AGENTS.md and SECURITY.md for security-model discoverability#2596

Open
potiuk wants to merge 1 commit into
apache:developfrom
potiuk:security-model-discoverability
Open

Add AGENTS.md and SECURITY.md for security-model discoverability#2596
potiuk wants to merge 1 commit into
apache:developfrom
potiuk:security-model-discoverability

Conversation

@potiuk

@potiuk potiuk commented Jun 12, 2026

Copy link
Copy Markdown
Member

This is a proposal for the PMC to review — please correct, reject, or discuss as needed. Nothing here is a requirement.

This adds AGENTS.md + SECURITY.md so an automated scan agent (and any other tooling) can mechanically discover the project's security model via the conventional AGENTS.md → SECURITY.md → model chain. Both files only point at the existing in-repo draft-THREAT-MODEL.md — no model content is added or changed here.

Context: the ASF Security team is preparing PLC4X for an automated agentic security scan we're piloting. Such scans refuse to run unless the model is discoverable by that path (refusing upfront beats a noise-heavy run against a model the agent never found). The Security team has been in touch separately on the PMC's private list with the program details.

Two things the PMC may want to do as follow-ups (not needed for this PR):

  • Rename draft-THREAT-MODEL.mdTHREAT_MODEL.md once you're happy with it (then this PR's links update to match).
  • Work through the §14 Open questions for the maintainers in that draft — those are the spots where we inferred a position and would like your confirmation.

Questions / pushback welcome — happy to adjust wording or move the section to fit the project's house style.

Adds the conventional AGENTS.md -> SECURITY.md -> model discoverability chain, pointing at the existing in-repo draft-THREAT-MODEL.md. No model content is changed.

Generated-by: Claude Opus 4.8 (1M context)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant