Skip to content

Resolve an additional 4 "inferred" notations to "maintainer"#1312

Merged
lmccay merged 4 commits into
masterfrom
pr-1293
Jul 18, 2026
Merged

Resolve an additional 4 "inferred" notations to "maintainer"#1312
lmccay merged 4 commits into
masterfrom
pr-1293

Conversation

@lmccay

@lmccay lmccay commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

What changes were proposed in this pull request?

The 4 gap fixes — promoted (inferred) → (maintainer, 2026-07-09 — L. McCay confirmed …):

  1. §6 line 276 — per-surface trust table (Q19, your "Agreed")
  2. §6 line 298 — size/shape/rate resource bound (Q20)
  3. §9 line 422 — bearer-token false friend (Q18/Q25, "Agree with the proposed statement")
  4. §9 line 428 — backend-hop TLS false friend (Q16)

Two consistency fixes to keep the doc's self-description honest:

  • Updated the Draft confidence tally from the stale ~14/~20/~22 to the accurate ~17 documented / ~39 maintainer / ~11 inferred, and added the newly-promoted items to the "now maintainer" list.
  • Added Q8 (§4 data-flow/reachability) to both the "still inferred" summary and the §14 Wave 3 open list — it was genuinely still open but omitted from both.

How was this patch tested?

Threat model document only - no testing required.

potiuk and others added 4 commits July 2, 2026 20:40
Adds a v0 THREAT_MODEL.md for Apache Knox drafted by the ASF Security team
for the Knox PMC to review, adjust, and own (path 3 of the Frontier Model
Preparation pre-flight, per the Knox PMC's 2026-07-02 go-ahead), plus the
discoverability wiring: AGENTS.md -> SECURITY.md -> THREAT_MODEL.md.

Generated-by: Claude (Opus 4.8, 1M context)
…nore

apache-rat 0.13 (this repo's version) does not recognise the short SPDX
identifier, so it flagged THREAT_MODEL.md / SECURITY.md / AGENTS.md. Switching
to the full AL-2.0 header (HTML comment) makes them pass the license check on
every RAT version, so the .ratignore exemption is no longer needed.

Generated-by: Claude Code
Larry McCay's 2026-07-09 line-by-line review folded in: Wave 1–3
core + meta §14 answers recorded and the corresponding claims
promoted to (maintainer). Notably: ungated HeaderPreAuth
reclassified OUT-OF-MODEL (operator responsibility) per Q14;
backend-hop TLS documented as required for SPNEGO; the
WebAppSecProvider / regexp-whitelist responsibility split added;
"identity certificate" wording fixed.

Generated-by: Claude Code (Claude Opus 4.8)
@lmccay
lmccay merged commit 94f394a into master Jul 18, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants