vlsi opened a new pull request, #5215:
URL: https://github.com/apache/calcite/pull/5215

   ## Why
   AGENTS.md restated the full security threat model — the SPI class-loading 
gate, the pushed-down-SQL rule, the "not a vulnerability" list, and the 
"downstream responsibilities" list — that already lives in 
[SECURITY.md](https://github.com/apache/calcite/blob/main/SECURITY.md) and the 
linked threat model. Keeping two copies means they can drift out of sync.
   
   ## What
   Cuts AGENTS.md down to a one-paragraph description of what Apache Calcite 
is, plus a link to SECURITY.md for anything security-related, instead of 
duplicating its content.
   
   ## How to verify
   Docs only; no production code touched. Read the new 
[AGENTS.md](https://github.com/apache/calcite/blob/claude/agents-md-minimal-deb238/AGENTS.md)
 and confirm it still points agents at SECURITY.md.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to