potiuk opened a new pull request, #15706: URL: https://github.com/apache/grails-core/pull/15706
**This is a proposal for the PMC to review — please correct, reject, or discuss as needed.** Nothing here is a requirement; the maintainer is the decision-maker. This adds a "Security model" pointer to the *Reporting Vulnerabilities* section of `AGENTS.md` so an automated scan agent can mechanically discover the project's security model via the conventional `AGENTS.md → SECURITY.md → THREAT_MODEL.md` chain. `SECURITY.md` and `THREAT_MODEL.md` already exist on this branch; `AGENTS.md` currently points only at the generic ASF Security Team page, so the chain doesn't start from there. This PR adds only that link — no model content changes. Context: the ASF Security team is preparing the project for an automated agentic security scan we're piloting. Such scans refuse to run if the model isn't mechanically discoverable by that path (refusing upfront beats wasting reviewer cycles on a noise-heavy run against a model the agent never found). Discoverability is the one hard gate; everything else is suggestion. Questions / pushback welcome — happy to move the line or adjust wording to match house style. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
