ppkarwasz opened a new pull request, #67: URL: https://github.com/apache/commons-secure-xml/pull/67
Restructures `SECURITY.md` from two bare links into four sections: 1. **Supported Versions** — security fixes are applied to the 1.x release line. 2. **Reporting Findings** — private reporting through the [Apache Commons Security Page](https://commons.apache.org/security.html); no public issues or PRs for security findings. 3. **Library Threat Model** — the threat model that findings against the library are triaged against. 4. **Supply-Chain Risks** — the trust assumptions of the repository workflows: `apache/commons-*` repositories are fully trusted (same project, governance, and access controls), and trusting GitHub-owned `actions/*` and `github/*` is an accepted risk, since GitHub already runs the workflows and holds the secrets. Reports about unpinned (branch/tag) references into either are out of scope. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
