Skip to content

Add AGENTS.md with security-model link for agent discoverability#1226

Merged
jamesfredley merged 2 commits into
apache:8.0.xfrom
potiuk:asf-security/agents-md-init-2026-05-31
Jun 1, 2026
Merged

Add AGENTS.md with security-model link for agent discoverability#1226
jamesfredley merged 2 commits into
apache:8.0.xfrom
potiuk:asf-security/agents-md-init-2026-05-31

Conversation

@potiuk
Copy link
Copy Markdown
Member

@potiuk potiuk commented May 31, 2026

This is a proposal for the PMC to review — please correct, reject, or discuss as needed. Nothing here is a requirement; the maintainer is the decision-maker.

This adds an AGENTS.md so an automated scan agent can mechanically discover the project's security model via the conventional AGENTS.md → SECURITY.md → THREAT_MODEL.md chain. SECURITY.md and THREAT_MODEL.md already exist on this branch; the repo just has no AGENTS.md for the chain to start from. This PR adds only that file — no model content changes.

Context: the ASF Security team is preparing the project for an automated agentic security scan we're piloting. Such scans refuse to run if the model isn't mechanically discoverable by that path. Discoverability is the one hard gate; everything else is suggestion.

Questions / pushback welcome — happy to adjust the file to match house style.

Resolve add/add conflict in AGENTS.md: keep the comprehensive agent
guide that landed on 8.0.x and incorporate this PR's contributions -
the automated-agent intro paragraph and the security-scanner guidance
pointing agents at SECURITY.md and THREAT_MODEL.md before reporting
issues.

Assisted-by: claude-code:claude-4.8-opus
@jamesfredley jamesfredley merged commit 9a6e0c2 into apache:8.0.x Jun 1, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants