Hi Stamatis,

Thanks for investigating the patterns. I agree with your proposal;
it's the best approach for our project.

Best,
Okumin

On Thu, Sep 24, 2026 at 5:05 PM Stamatis Zampetakis <[email protected]> wrote:
>
> There have been some side questions on how to provide credits for
> these findings coming through the Glasswing scan and deserve a CVE
> publication. I took a quick look in the [email protected] where CVEs
> are published and found the following patterns used by other ASF
> projects.
>
> ## Apache Sling
>
> The Apache Software Foundation (finder)
> Claude Code (tool)
>
> ## Apache Airflow
>
> Claude Security Scans (tool)
> Jarek Potiuk (remediation developer)
>
> ## Apache Neethi
>
> This issue was found using Claude agents to study the security of
> open-source projects (finder)
>
> ## Apache Storm
>
> The ASF using Claude Agents (finder)
>
> Personally, the one I like the most is the Airflow pattern. I would
> propose to use that with a small addition to acknowledge the reviewer.
>
> ## Apache Hive
>
> Claude Security Scans (tool)
> Stamatis Zampetakis (remediation developer)
> Alice Hacker (remediation reviewer)
>
> Best,
> Stamatis
>
> On Wed, Sep 9, 2026 at 10:20 AM Stamatis Zampetakis <[email protected]> 
> wrote:
> >
> > Hi all,
> >
> > Various ASF projects including Hive are using AI to find security 
> > vulnerabilities and harden security. This topic was confidential till now 
> > so we were not allowed to publicly talk about what is happening behind the 
> > scenes. From now on, the news is public and you can read all details in the 
> > official ASF blog post [1].
> >
> > The Glasswing scan for Hive was delivered in [email protected] and 
> > the team is actively working on triaging and fixing the reported issues. 
> > Hive PMC and committers can (and are strongly encouraged to) subscribe to 
> > the security mailing list (using their @apache.org address) to follow the 
> > progress and help out in this initiative.
> >
> > Best,
> > Stamatis
> >
> > [1] 
> > https://news.apache.org/foundation/entry/security-scanning-at-foundation-scale

Reply via email to