vlsi opened a new pull request, #5215: URL: https://github.com/apache/calcite/pull/5215
## Why AGENTS.md restated the full security threat model — the SPI class-loading gate, the pushed-down-SQL rule, the "not a vulnerability" list, and the "downstream responsibilities" list — that already lives in [SECURITY.md](https://github.com/apache/calcite/blob/main/SECURITY.md) and the linked threat model. Keeping two copies means they can drift out of sync. ## What Cuts AGENTS.md down to a one-paragraph description of what Apache Calcite is, plus a link to SECURITY.md for anything security-related, instead of duplicating its content. ## How to verify Docs only; no production code touched. Read the new [AGENTS.md](https://github.com/apache/calcite/blob/claude/agents-md-minimal-deb238/AGENTS.md) and confirm it still points agents at SECURITY.md. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
