There have been some side questions on how to provide credits for these findings coming through the Glasswing scan and deserve a CVE publication. I took a quick look in the [email protected] where CVEs are published and found the following patterns used by other ASF projects.
## Apache Sling The Apache Software Foundation (finder) Claude Code (tool) ## Apache Airflow Claude Security Scans (tool) Jarek Potiuk (remediation developer) ## Apache Neethi This issue was found using Claude agents to study the security of open-source projects (finder) ## Apache Storm The ASF using Claude Agents (finder) Personally, the one I like the most is the Airflow pattern. I would propose to use that with a small addition to acknowledge the reviewer. ## Apache Hive Claude Security Scans (tool) Stamatis Zampetakis (remediation developer) Alice Hacker (remediation reviewer) Best, Stamatis On Wed, Sep 9, 2026 at 10:20 AM Stamatis Zampetakis <[email protected]> wrote: > > Hi all, > > Various ASF projects including Hive are using AI to find security > vulnerabilities and harden security. This topic was confidential till now so > we were not allowed to publicly talk about what is happening behind the > scenes. >From now on, the news is public and you can read all details in the > official ASF blog post [1]. > > The Glasswing scan for Hive was delivered in [email protected] and the > team is actively working on triaging and fixing the reported issues. Hive PMC > and committers can (and are strongly encouraged to) subscribe to the security > mailing list (using their @apache.org address) to follow the progress and > help out in this initiative. > > Best, > Stamatis > > [1] > https://news.apache.org/foundation/entry/security-scanning-at-foundation-scale
