Skip to content

Commit 4d89748

Browse files
authored
Merge pull request #363 from potiuk/asf-security/threat-model-discoverability-2026-07-15
Wire the security threat model for agent discoverability (AGENTS.md + SECURITY.md); rename draft-THREAT-MODEL.md -> THREAT_MODEL.md
2 parents aa2d561 + 72b1c41 commit 4d89748

3 files changed

Lines changed: 47 additions & 0 deletions

File tree

AGENTS.md

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
# Agent guidance
2+
3+
This file is read by automated agents (security scanners, code
4+
analyzers, AI assistants) operating on this repository. It points
5+
them at the human-authored references they should consult before
6+
producing output.
7+
8+
## Security
9+
10+
Security model: [SECURITY.md](./SECURITY.md)
11+
12+
Agents that scan this repository should consult `SECURITY.md` and the
13+
threat model it links before reporting issues.

SECURITY.md

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
<!--
2+
Licensed to the Apache Software Foundation (ASF) under one
3+
or more contributor license agreements. See the NOTICE file
4+
distributed with this work for additional information
5+
regarding copyright ownership. The ASF licenses this file
6+
to you under the Apache License, Version 2.0 (the
7+
"License"); you may not use this file except in compliance
8+
with the License. You may obtain a copy of the License at
9+
10+
http://www.apache.org/licenses/LICENSE-2.0
11+
12+
Unless required by applicable law or agreed to in writing,
13+
software distributed under the License is distributed on an
14+
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15+
KIND, either express or implied. See the License for the
16+
specific language governing permissions and limitations
17+
under the License.
18+
-->
19+
20+
# Security Policy
21+
22+
## Reporting a Vulnerability
23+
24+
Apache Jackrabbit follows the [Apache Software Foundation security
25+
process](https://www.apache.org/security/). Please report suspected
26+
vulnerabilities privately to `security@apache.org` (the Jackrabbit PMC
27+
is reachable via `private@jackrabbit.apache.org`). Do not open public
28+
GitHub issues or pull requests for security reports.
29+
30+
## Threat Model
31+
32+
What the project treats as in scope and out of scope, the security
33+
properties it provides and disclaims, the adversary model, and how
34+
findings are triaged are documented in [THREAT_MODEL.md](./THREAT_MODEL.md).
File renamed without changes.

0 commit comments

Comments
 (0)