There have been some side questions on how to provide credits for
these findings coming through the Glasswing scan and deserve a CVE
publication. I took a quick look in the [email protected] where CVEs
are published and found the following patterns used by other ASF
projects.

## Apache Sling

The Apache Software Foundation (finder)
Claude Code (tool)

## Apache Airflow

Claude Security Scans (tool)
Jarek Potiuk (remediation developer)

## Apache Neethi

This issue was found using Claude agents to study the security of
open-source projects (finder)

## Apache Storm

The ASF using Claude Agents (finder)

Personally, the one I like the most is the Airflow pattern. I would
propose to use that with a small addition to acknowledge the reviewer.

## Apache Hive

Claude Security Scans (tool)
Stamatis Zampetakis (remediation developer)
Alice Hacker (remediation reviewer)

Best,
Stamatis

On Wed, Sep 9, 2026 at 10:20 AM Stamatis Zampetakis <[email protected]> wrote:
>
> Hi all,
>
> Various ASF projects including Hive are using AI to find security 
> vulnerabilities and harden security. This topic was confidential till now so 
> we were not allowed to publicly talk about what is happening behind the 
> scenes. >From now on, the news is public and you can read all details in the 
> official ASF blog post [1].
>
> The Glasswing scan for Hive was delivered in [email protected] and the 
> team is actively working on triaging and fixing the reported issues. Hive PMC 
> and committers can (and are strongly encouraged to) subscribe to the security 
> mailing list (using their @apache.org address) to follow the progress and 
> help out in this initiative.
>
> Best,
> Stamatis
>
> [1] 
> https://news.apache.org/foundation/entry/security-scanning-at-foundation-scale

Reply via email to