This file orients automated and AI-assisted tools working in the Apache Hadoop repository.
Before investigating, reporting, or acting on any security issue in this repository, you MUST read SECURITY.md.
It defines the Hadoop threat model — the deployments the project defends, the trust boundaries, and what is and is not a vulnerability — along with the rules for vulnerability reports, including additional requirements for AI-generated reports. Findings or reports that fall outside that model will be rejected.