lukaszlenart opened a new pull request, #1917:
URL: https://github.com/apache/struts/pull/1917

   Both security skills stated that a CVE is requested only after the fixed 
release is out, phrased as a hard constraint. It is a PMC practice (a silent 
consensus from earlier discussions), not an ASF rule — the ASF committer 
security process permits allocating a CVE earlier and sharing the id with the 
reporter.
   
   ## Changes
   
   - `triaging-security-reports/SKILL.md` — reword the CVE guidance from 
"requested once the fixed release is out, never at triage" to our-practice / 
PMC's-call framing, noting ASF permits earlier allocation.
   - `creating-security-bulletins/SKILL.md` — same reframe on the CVE 
placeholder section.
   - Soften the matching red-flag and common-mistake lines to say CVE *timing* 
is a PMC choice, not a fixed rule.
   
   The operational guidance is preserved: a triage reply must still not commit 
the project to a CVE or its timing.
   
   Docs-only change under `.claude/` — no Jira ticket, conventional-commit form 
per `CLAUDE.md`.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to