@florenciocano@infosec.exchange
Post #3852223
2026-07-15 21:26 UTC
@iamamoose@infosec.exchange Mark, you said "outside of the threat model". Is that threat model documented anywhere? I ask because I think the threat model could be used to filter security issues and I would like to see Apache's
Replies (1)
-
@iamamoose@infosec.exchange 2026-07-16 06:31
@florenciocano@infosec.exchange right! That's actually part of the solution. Each project is responsible for creating their own threat model and we've been working with them to ensure they're published and llm-findable, not just from a list on security.apache.org but in SECURITY.md files etc