Skip to content

Commit 38b674f

Browse files
authored
Add AGENTS.md + SECURITY.md wiring for security-model discoverability (#13554)
1 parent 4c0a3e1 commit 38b674f

2 files changed

Lines changed: 66 additions & 0 deletions

File tree

AGENTS.md

Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
<!--
2+
Licensed to the Apache Software Foundation (ASF) under one
3+
or more contributor license agreements. See the NOTICE file
4+
distributed with this work for additional information
5+
regarding copyright ownership. The ASF licenses this file
6+
to you under the Apache License, Version 2.0 (the
7+
"License"); you may not use this file except in compliance
8+
with the License. You may obtain a copy of the License at
9+
10+
http://www.apache.org/licenses/LICENSE-2.0
11+
12+
Unless required by applicable law or agreed to in writing,
13+
software distributed under the License is distributed on an
14+
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15+
KIND, either express or implied. See the License for the
16+
specific language governing permissions and limitations
17+
under the License.
18+
-->
19+
20+
# Agent Guide for Apache CloudStack
21+
22+
This file is read by automated agents (security scanners, code
23+
analyzers, AI assistants) operating on this repository.
24+
25+
## Security
26+
27+
Security model: [SECURITY.md](./SECURITY.md)
28+
29+
Agents that scan this repository should consult `SECURITY.md` and the
30+
threat model it links before reporting issues.
31+
32+
The project-wide security threat model is linked from `SECURITY.md`.

SECURITY.md

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
<!--
2+
Licensed to the Apache Software Foundation (ASF) under one
3+
or more contributor license agreements. See the NOTICE file
4+
distributed with this work for additional information
5+
regarding copyright ownership. The ASF licenses this file
6+
to you under the Apache License, Version 2.0 (the
7+
"License"); you may not use this file except in compliance
8+
with the License. You may obtain a copy of the License at
9+
10+
http://www.apache.org/licenses/LICENSE-2.0
11+
12+
Unless required by applicable law or agreed to in writing,
13+
software distributed under the License is distributed on an
14+
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15+
KIND, either express or implied. See the License for the
16+
specific language governing permissions and limitations
17+
under the License.
18+
-->
19+
20+
# Security Policy
21+
22+
## Reporting a Vulnerability
23+
24+
`apache/cloudstack` follows the [Apache Software Foundation security process](https://www.apache.org/security/). Please report suspected
25+
vulnerabilities privately to `security@apache.org`; do not open public GitHub issues or pull requests for security reports.
26+
27+
For more details, see https://cloudstack.apache.org/security.html.
28+
29+
## Threat Model
30+
31+
What the project treats as in scope and out of scope, the security
32+
properties it provides and disclaims, the adversary model, and how
33+
findings are triaged are documented in the project-wide threat model:
34+
[draft-THREAT-MODEL.md](draft-THREAT-MODEL.md).

0 commit comments

Comments
 (0)