potiuk opened a new pull request, #2596:
URL: https://github.com/apache/plc4x/pull/2596

   **This is a proposal for the PMC to review — please correct, reject, or 
discuss as needed.** Nothing here is a requirement.
   
   This adds `AGENTS.md` + `SECURITY.md` so an automated scan agent (and any 
other tooling) can mechanically discover the project's security model via the 
conventional `AGENTS.md → SECURITY.md → model` chain. Both files only point at 
the existing in-repo `draft-THREAT-MODEL.md` — no model content is added or 
changed here.
   
   Context: the ASF Security team is preparing PLC4X for an automated agentic 
security scan we're piloting. Such scans refuse to run unless the model is 
discoverable by that path (refusing upfront beats a noise-heavy run against a 
model the agent never found). The Security team has been in touch separately on 
the PMC's private list with the program details.
   
   Two things the PMC may want to do as follow-ups (not needed for this PR):
   - Rename `draft-THREAT-MODEL.md` → `THREAT_MODEL.md` once you're happy with 
it (then this PR's links update to match).
   - Work through the `§14 Open questions for the maintainers` in that draft — 
those are the spots where we inferred a position and would like your 
confirmation.
   
   Questions / pushback welcome — happy to adjust wording or move the section 
to fit the project's house style.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to