potiuk opened a new pull request, #2596: URL: https://github.com/apache/plc4x/pull/2596
**This is a proposal for the PMC to review — please correct, reject, or discuss as needed.** Nothing here is a requirement. This adds `AGENTS.md` + `SECURITY.md` so an automated scan agent (and any other tooling) can mechanically discover the project's security model via the conventional `AGENTS.md → SECURITY.md → model` chain. Both files only point at the existing in-repo `draft-THREAT-MODEL.md` — no model content is added or changed here. Context: the ASF Security team is preparing PLC4X for an automated agentic security scan we're piloting. Such scans refuse to run unless the model is discoverable by that path (refusing upfront beats a noise-heavy run against a model the agent never found). The Security team has been in touch separately on the PMC's private list with the program details. Two things the PMC may want to do as follow-ups (not needed for this PR): - Rename `draft-THREAT-MODEL.md` → `THREAT_MODEL.md` once you're happy with it (then this PR's links update to match). - Work through the `§14 Open questions for the maintainers` in that draft — those are the spots where we inferred a position and would like your confirmation. Questions / pushback welcome — happy to adjust wording or move the section to fit the project's house style. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
