mirror of
https://github.com/apache/cloudstack
synced 2026-08-02 05:26:35 +00:00
Add AGENTS.md + SECURITY.md wiring for security-model discoverability (#13554)
This commit is contained in:
parent
4c0a3e1499
commit
38b674f442
32
AGENTS.md
Normal file
32
AGENTS.md
Normal file
@ -0,0 +1,32 @@
|
|||||||
|
<!--
|
||||||
|
Licensed to the Apache Software Foundation (ASF) under one
|
||||||
|
or more contributor license agreements. See the NOTICE file
|
||||||
|
distributed with this work for additional information
|
||||||
|
regarding copyright ownership. The ASF licenses this file
|
||||||
|
to you under the Apache License, Version 2.0 (the
|
||||||
|
"License"); you may not use this file except in compliance
|
||||||
|
with the License. You may obtain a copy of the License at
|
||||||
|
|
||||||
|
http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing,
|
||||||
|
software distributed under the License is distributed on an
|
||||||
|
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||||
|
KIND, either express or implied. See the License for the
|
||||||
|
specific language governing permissions and limitations
|
||||||
|
under the License.
|
||||||
|
-->
|
||||||
|
|
||||||
|
# Agent Guide for Apache CloudStack
|
||||||
|
|
||||||
|
This file is read by automated agents (security scanners, code
|
||||||
|
analyzers, AI assistants) operating on this repository.
|
||||||
|
|
||||||
|
## Security
|
||||||
|
|
||||||
|
Security model: [SECURITY.md](./SECURITY.md)
|
||||||
|
|
||||||
|
Agents that scan this repository should consult `SECURITY.md` and the
|
||||||
|
threat model it links before reporting issues.
|
||||||
|
|
||||||
|
The project-wide security threat model is linked from `SECURITY.md`.
|
||||||
34
SECURITY.md
Normal file
34
SECURITY.md
Normal file
@ -0,0 +1,34 @@
|
|||||||
|
<!--
|
||||||
|
Licensed to the Apache Software Foundation (ASF) under one
|
||||||
|
or more contributor license agreements. See the NOTICE file
|
||||||
|
distributed with this work for additional information
|
||||||
|
regarding copyright ownership. The ASF licenses this file
|
||||||
|
to you under the Apache License, Version 2.0 (the
|
||||||
|
"License"); you may not use this file except in compliance
|
||||||
|
with the License. You may obtain a copy of the License at
|
||||||
|
|
||||||
|
http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing,
|
||||||
|
software distributed under the License is distributed on an
|
||||||
|
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||||
|
KIND, either express or implied. See the License for the
|
||||||
|
specific language governing permissions and limitations
|
||||||
|
under the License.
|
||||||
|
-->
|
||||||
|
|
||||||
|
# Security Policy
|
||||||
|
|
||||||
|
## Reporting a Vulnerability
|
||||||
|
|
||||||
|
`apache/cloudstack` follows the [Apache Software Foundation security process](https://www.apache.org/security/). Please report suspected
|
||||||
|
vulnerabilities privately to `security@apache.org`; do not open public GitHub issues or pull requests for security reports.
|
||||||
|
|
||||||
|
For more details, see https://cloudstack.apache.org/security.html.
|
||||||
|
|
||||||
|
## Threat Model
|
||||||
|
|
||||||
|
What the project treats as in scope and out of scope, the security
|
||||||
|
properties it provides and disclaims, the adversary model, and how
|
||||||
|
findings are triaged are documented in the project-wide threat model:
|
||||||
|
[draft-THREAT-MODEL.md](draft-THREAT-MODEL.md).
|
||||||
Loading…
Reference in New Issue
Block a user