The GitHub Actions job "CodeQL" on grails-core.git/docs/threat-model-8.0.x has 
succeeded.
Run started by GitHub user jamesfredley (triggered by jamesfredley).

Head commit for run:
6a760c4002f91c40a06cbbf821d4aa8f741d104e / James Fredley 
<[email protected]>
Add THREAT_MODEL.md per the Apache security threat-model rubric

Adds a project threat model that defines the implicit security contract
between the Grails framework and its downstream users: what is in scope,
what is out, which security properties the framework claims, which it
explicitly disclaims, and how inbound vulnerability reports and tool
findings are triaged.

The document follows the structure mandated by the threat-model-producer
rubric maintained by the ASF Security team (public mirror at
https://gist.github.com/potiuk/da14a826283038ddfe38cc9fe6310573), covering
sections 1 through 15 inclusive, with provenance tags on every non-trivial
claim. Existing security guidance in grails-doc/src/en/guide/security/ is
mined as the documented source-of-truth and back-mapped in Appendix A;
nothing in the existing documentation is dropped, weakened, or contradicted.

This is a DRAFT. The document is published in draft-first mode (rubric
section 3.2). 22 open questions for the PMC are collected in section 14,
grouped into three waves and framed as proposed answers for confirmation
or correction. Inferred claims should be promoted to maintainer-confirmed
as those answers land.

Additions:
- THREAT_MODEL.md: prose document, 15 sections plus a back-map appendix.
- threat-model.yaml: machine-readable companion (rubric section 15) for
  automated and AI-assisted triage tooling. Derived from the prose
  document; the prose remains canonical.
- SECURITY.md: cross-reference paragraph pointing at THREAT_MODEL.md, per
  rubric section 1.

Assisted-by: claude-code:claude-opus-4-7

Report URL: https://github.com/apache/grails-core/actions/runs/25925035223

With regards,
GitHub Actions via GitBox

Reply via email to