mirror of
https://github.com/apache/cloudstack
synced 2026-08-02 05:26:35 +00:00
Add AGENTS.md + SECURITY.md wiring for security-model discoverability (#13554)
This commit is contained in:
parent
4c0a3e1499
commit
38b674f442
32
AGENTS.md
Normal file
32
AGENTS.md
Normal file
@ -0,0 +1,32 @@
|
||||
<!--
|
||||
Licensed to the Apache Software Foundation (ASF) under one
|
||||
or more contributor license agreements. See the NOTICE file
|
||||
distributed with this work for additional information
|
||||
regarding copyright ownership. The ASF licenses this file
|
||||
to you under the Apache License, Version 2.0 (the
|
||||
"License"); you may not use this file except in compliance
|
||||
with the License. You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing,
|
||||
software distributed under the License is distributed on an
|
||||
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||
KIND, either express or implied. See the License for the
|
||||
specific language governing permissions and limitations
|
||||
under the License.
|
||||
-->
|
||||
|
||||
# Agent Guide for Apache CloudStack
|
||||
|
||||
This file is read by automated agents (security scanners, code
|
||||
analyzers, AI assistants) operating on this repository.
|
||||
|
||||
## Security
|
||||
|
||||
Security model: [SECURITY.md](./SECURITY.md)
|
||||
|
||||
Agents that scan this repository should consult `SECURITY.md` and the
|
||||
threat model it links before reporting issues.
|
||||
|
||||
The project-wide security threat model is linked from `SECURITY.md`.
|
||||
34
SECURITY.md
Normal file
34
SECURITY.md
Normal file
@ -0,0 +1,34 @@
|
||||
<!--
|
||||
Licensed to the Apache Software Foundation (ASF) under one
|
||||
or more contributor license agreements. See the NOTICE file
|
||||
distributed with this work for additional information
|
||||
regarding copyright ownership. The ASF licenses this file
|
||||
to you under the Apache License, Version 2.0 (the
|
||||
"License"); you may not use this file except in compliance
|
||||
with the License. You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing,
|
||||
software distributed under the License is distributed on an
|
||||
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
||||
KIND, either express or implied. See the License for the
|
||||
specific language governing permissions and limitations
|
||||
under the License.
|
||||
-->
|
||||
|
||||
# Security Policy
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
`apache/cloudstack` follows the [Apache Software Foundation security process](https://www.apache.org/security/). Please report suspected
|
||||
vulnerabilities privately to `security@apache.org`; do not open public GitHub issues or pull requests for security reports.
|
||||
|
||||
For more details, see https://cloudstack.apache.org/security.html.
|
||||
|
||||
## Threat Model
|
||||
|
||||
What the project treats as in scope and out of scope, the security
|
||||
properties it provides and disclaims, the adversary model, and how
|
||||
findings are triaged are documented in the project-wide threat model:
|
||||
[draft-THREAT-MODEL.md](draft-THREAT-MODEL.md).
|
||||
Loading…
Reference in New Issue
Block a user