potiuk opened a new pull request, #141:
URL: https://github.com/apache/airflow-steward/pull/141

   ## Summary
   
   - Adds a `### Reporter claims about dependencies: conditional language only` 
rule under "Writing and editing documentation" in `AGENTS.md`.
   - When a reporter says the vulnerability lives in **one of the project's 
dependencies**, drafted replies must not adopt the claim as fact — the project 
has no authority to confirm a vulnerability in code it does not maintain.
   - Rule lists explicit do / don't phrasings (forward to the dependency's 
maintainers, condition the assessment on their confirmation) and pairs with the 
existing *Reporter-supplied CVSS scores are informational only* rule (same 
shape — a position from the reporter the team has not yet evaluated).
   - Carves out the case where the report actually describes a flaw in the 
project's own code that *happens to involve* a dependency — at that point the 
finding is ours and the brevity rule above takes over.
   
   Doctoc TOC entry added.
   
   ## Why now
   
   A real airflow-s thread surfaced the failure mode: it is easy for a drafted 
reply to read like an endorsement of a third-party vulnerability claim, which 
the reporter can then forward as evidence — pressuring the dependency's 
maintainers and damaging the relationship the project depends on.
   
   ## Test plan
   
   - [x] `prek run --files AGENTS.md` passes (markdownlint, typos, doctoc, 
trailing-whitespace).
   - [ ] CI green on the PR.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to