ppkarwasz opened a new pull request, #67:
URL: https://github.com/apache/commons-secure-xml/pull/67

   Restructures `SECURITY.md` from two bare links into four sections:
   
   1. **Supported Versions** — security fixes are applied to the 1.x release 
line.
   2. **Reporting Findings** — private reporting through the [Apache Commons 
Security Page](https://commons.apache.org/security.html); no public issues or 
PRs for security findings.
   3. **Library Threat Model** — the threat model that findings against the 
library are triaged against.
   4. **Supply-Chain Risks** — the trust assumptions of the repository 
workflows: `apache/commons-*` repositories are fully trusted (same project, 
governance, and access controls), and trusting GitHub-owned `actions/*` and 
`github/*` is an accepted risk, since GitHub already runs the workflows and 
holds the secrets. Reports about unpinned (branch/tag) references into either 
are out of scope.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to