The GitHub Actions job "CodeQL" on grails-core.git/docs/threat-model-8.0.x has succeeded. Run started by GitHub user jamesfredley (triggered by jamesfredley).
Head commit for run: 6a760c4002f91c40a06cbbf821d4aa8f741d104e / James Fredley <[email protected]> Add THREAT_MODEL.md per the Apache security threat-model rubric Adds a project threat model that defines the implicit security contract between the Grails framework and its downstream users: what is in scope, what is out, which security properties the framework claims, which it explicitly disclaims, and how inbound vulnerability reports and tool findings are triaged. The document follows the structure mandated by the threat-model-producer rubric maintained by the ASF Security team (public mirror at https://gist.github.com/potiuk/da14a826283038ddfe38cc9fe6310573), covering sections 1 through 15 inclusive, with provenance tags on every non-trivial claim. Existing security guidance in grails-doc/src/en/guide/security/ is mined as the documented source-of-truth and back-mapped in Appendix A; nothing in the existing documentation is dropped, weakened, or contradicted. This is a DRAFT. The document is published in draft-first mode (rubric section 3.2). 22 open questions for the PMC are collected in section 14, grouped into three waves and framed as proposed answers for confirmation or correction. Inferred claims should be promoted to maintainer-confirmed as those answers land. Additions: - THREAT_MODEL.md: prose document, 15 sections plus a back-map appendix. - threat-model.yaml: machine-readable companion (rubric section 15) for automated and AI-assisted triage tooling. Derived from the prose document; the prose remains canonical. - SECURITY.md: cross-reference paragraph pointing at THREAT_MODEL.md, per rubric section 1. Assisted-by: claude-code:claude-opus-4-7 Report URL: https://github.com/apache/grails-core/actions/runs/25925035223 With regards, GitHub Actions via GitBox
