potiuk opened a new pull request, #15706:
URL: https://github.com/apache/grails-core/pull/15706

   **This is a proposal for the PMC to review — please correct, reject, or 
discuss as needed.** Nothing here is a requirement; the maintainer is the 
decision-maker.
   
   This adds a "Security model" pointer to the *Reporting Vulnerabilities* 
section of `AGENTS.md` so an automated scan agent can mechanically discover the 
project's security model via the conventional `AGENTS.md → SECURITY.md → 
THREAT_MODEL.md` chain. `SECURITY.md` and `THREAT_MODEL.md` already exist on 
this branch; `AGENTS.md` currently points only at the generic ASF Security Team 
page, so the chain doesn't start from there. This PR adds only that link — no 
model content changes.
   
   Context: the ASF Security team is preparing the project for an automated 
agentic security scan we're piloting. Such scans refuse to run if the model 
isn't mechanically discoverable by that path (refusing upfront beats wasting 
reviewer cycles on a noise-heavy run against a model the agent never found). 
Discoverability is the one hard gate; everything else is suggestion.
   
   Questions / pushback welcome — happy to move the line or adjust wording to 
match house style.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to