Hi Stamatis,
Thanx for starting the thread. I am +1 to the proposal, adding the
reviewer also makes sense to me

-Ayush

On Fri, 25 Sept 2026 at 10:29, Shohei Okumiya <[email protected]> wrote:
>
> Hi Stamatis,
>
> Thanks for investigating the patterns. I agree with your proposal;
> it's the best approach for our project.
>
> Best,
> Okumin
>
> On Thu, Sep 24, 2026 at 5:05 PM Stamatis Zampetakis <[email protected]> 
> wrote:
> >
> > There have been some side questions on how to provide credits for
> > these findings coming through the Glasswing scan and deserve a CVE
> > publication. I took a quick look in the [email protected] where CVEs
> > are published and found the following patterns used by other ASF
> > projects.
> >
> > ## Apache Sling
> >
> > The Apache Software Foundation (finder)
> > Claude Code (tool)
> >
> > ## Apache Airflow
> >
> > Claude Security Scans (tool)
> > Jarek Potiuk (remediation developer)
> >
> > ## Apache Neethi
> >
> > This issue was found using Claude agents to study the security of
> > open-source projects (finder)
> >
> > ## Apache Storm
> >
> > The ASF using Claude Agents (finder)
> >
> > Personally, the one I like the most is the Airflow pattern. I would
> > propose to use that with a small addition to acknowledge the reviewer.
> >
> > ## Apache Hive
> >
> > Claude Security Scans (tool)
> > Stamatis Zampetakis (remediation developer)
> > Alice Hacker (remediation reviewer)
> >
> > Best,
> > Stamatis
> >
> > On Wed, Sep 9, 2026 at 10:20 AM Stamatis Zampetakis <[email protected]> 
> > wrote:
> > >
> > > Hi all,
> > >
> > > Various ASF projects including Hive are using AI to find security 
> > > vulnerabilities and harden security. This topic was confidential till now 
> > > so we were not allowed to publicly talk about what is happening behind 
> > > the scenes. From now on, the news is public and you can read all details 
> > > in the official ASF blog post [1].
> > >
> > > The Glasswing scan for Hive was delivered in [email protected] and 
> > > the team is actively working on triaging and fixing the reported issues. 
> > > Hive PMC and committers can (and are strongly encouraged to) subscribe to 
> > > the security mailing list (using their @apache.org address) to follow the 
> > > progress and help out in this initiative.
> > >
> > > Best,
> > > Stamatis
> > >
> > > [1] 
> > > https://news.apache.org/foundation/entry/security-scanning-at-foundation-scale

Reply via email to