Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Commit 38b674f

Browse filesBrowse files
authored
Add AGENTS.md + SECURITY.md wiring for security-model discoverability (#13554)
1 parent 4c0a3e1 commit 38b674f
Copy full SHA for 38b674f

2 files changed

+66Lines changed: 66 additions & 0 deletions

File tree

Expand file treeCollapse file tree
Open diff view settings
Filter options
Expand file treeCollapse file tree
Open diff view settings
Collapse file

‎AGENTS.md‎

Copy file name to clipboard
+32Lines changed: 32 additions & 0 deletions
  • Display the source diff
  • Display the rich diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
<!--
2+
Licensed to the Apache Software Foundation (ASF) under one
3+
or more contributor license agreements. See the NOTICE file
4+
distributed with this work for additional information
5+
regarding copyright ownership. The ASF licenses this file
6+
to you under the Apache License, Version 2.0 (the
7+
"License"); you may not use this file except in compliance
8+
with the License. You may obtain a copy of the License at
9+
10+
http://www.apache.org/licenses/LICENSE-2.0
11+
12+
Unless required by applicable law or agreed to in writing,
13+
software distributed under the License is distributed on an
14+
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15+
KIND, either express or implied. See the License for the
16+
specific language governing permissions and limitations
17+
under the License.
18+
-->
19+
20+
# Agent Guide for Apache CloudStack
21+
22+
This file is read by automated agents (security scanners, code
23+
analyzers, AI assistants) operating on this repository.
24+
25+
## Security
26+
27+
Security model: [SECURITY.md](./SECURITY.md)
28+
29+
Agents that scan this repository should consult `SECURITY.md` and the
30+
threat model it links before reporting issues.
31+
32+
The project-wide security threat model is linked from `SECURITY.md`.
Collapse file

‎SECURITY.md‎

Copy file name to clipboard
+34Lines changed: 34 additions & 0 deletions
  • Display the source diff
  • Display the rich diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
<!--
2+
Licensed to the Apache Software Foundation (ASF) under one
3+
or more contributor license agreements. See the NOTICE file
4+
distributed with this work for additional information
5+
regarding copyright ownership. The ASF licenses this file
6+
to you under the Apache License, Version 2.0 (the
7+
"License"); you may not use this file except in compliance
8+
with the License. You may obtain a copy of the License at
9+
10+
http://www.apache.org/licenses/LICENSE-2.0
11+
12+
Unless required by applicable law or agreed to in writing,
13+
software distributed under the License is distributed on an
14+
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15+
KIND, either express or implied. See the License for the
16+
specific language governing permissions and limitations
17+
under the License.
18+
-->
19+
20+
# Security Policy
21+
22+
## Reporting a Vulnerability
23+
24+
`apache/cloudstack` follows the [Apache Software Foundation security process](https://www.apache.org/security/). Please report suspected
25+
vulnerabilities privately to `security@apache.org`; do not open public GitHub issues or pull requests for security reports.
26+
27+
For more details, see https://cloudstack.apache.org/security.html.
28+
29+
## Threat Model
30+
31+
What the project treats as in scope and out of scope, the security
32+
properties it provides and disclaims, the adversary model, and how
33+
findings are triaged are documented in the project-wide threat model:
34+
[draft-THREAT-MODEL.md](draft-THREAT-MODEL.md).

0 commit comments

Comments
0 (0)
Morty Proxy This is a proxified and sanitized view of the page, visit original site.