Skip to content

[Improvement] Add AGENTS.md + SECURITY.md to make the security model discoverable#18310

Merged
SbloodyS merged 1 commit into
apache:devfrom
potiuk:asf-security/discoverability-2026-06-01
Jun 2, 2026
Merged

[Improvement] Add AGENTS.md + SECURITY.md to make the security model discoverable#18310
SbloodyS merged 1 commit into
apache:devfrom
potiuk:asf-security/discoverability-2026-06-01

Conversation

@potiuk
Copy link
Copy Markdown
Member

@potiuk potiuk commented Jun 1, 2026

This is a proposal for the DolphinScheduler PMC to review — please
correct, reject, or discuss as needed.
The maintainer is the
decision-maker; nothing here is a requirement.

This adds the conventional AGENTS.md → SECURITY.md discoverability
chain so an automated security scanner can mechanically locate the
project's existing security model. It does not add or change any
model content — your security model at
docs/docs/en/contribute/join/security-model.md is untouched; this just
makes it reachable via the standard chain.

  • SECURITY.md (new) — routes vulnerability reports to the ASF security
    process and points at the existing security model.
  • AGENTS.md (new) — a Security section routing agents along
    AGENTS.md → SECURITY.md → your security model.

Context: the ASF Security team is preparing the project for an automated
agentic security scan being piloted by the team. Such scans refuse to run
unless the model is discoverable by that conventional path —
discoverability is the one hard gate. No project source is touched.

Questions / pushback welcome — happy to adjust file placement or wording
to match the project's house style.

@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented Jun 1, 2026

Copy link
Copy Markdown
Member

@ruanwenjun ruanwenjun left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks.

@ruanwenjun ruanwenjun added this to the 3.4.2 milestone Jun 2, 2026
@SbloodyS SbloodyS changed the title Add AGENTS.md + SECURITY.md to make the security model discoverable [Chore] Add AGENTS.md + SECURITY.md to make the security model discoverable Jun 2, 2026
@SbloodyS SbloodyS added the chore label Jun 2, 2026
Copy link
Copy Markdown
Member

@SbloodyS SbloodyS left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1

@SbloodyS SbloodyS merged commit f5dff77 into apache:dev Jun 2, 2026
124 of 126 checks passed
@potiuk potiuk changed the title [Chore] Add AGENTS.md + SECURITY.md to make the security model discoverable [Improvement] Add AGENTS.md + SECURITY.md to make the security model discoverable Jun 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants