Re: [RFC] Describe the security model

Rich Bowen <[email protected]> Tue, 12 May 2026 13:45:27 -0400
Newsgroups gmane.comp.apache.devel
Message-ID <[email protected]>
(You=E2=80=99ve probably already done this but) I encourage you to talk =
with Jarek Potiuk, who has thought a LOT about this, and has a very =
elaborate setup over on Airflow to deal with this workflow.

> On May 12, 2026, at 1:23=E2=80=AFPM, Joe Orton <[email protected]> =
wrote:
>=20
> One thing which has come out of discussions about stemming the tide of=20=

> LLM reports is having a security model written down which a) the LLMs=20=

> can read, and b) we can use when assessing poor/slop reports.
>=20
> Most importantly the "we" in (b) should include the [email protected] team=20=

> who can hopefully use it to filter out the slop before "we" (this=20
> project's committers on [email protected]) see it.
>=20
> I find this task difficult to scope properly... it's hard to know what=20=

> should/should not be covered here. And there's probably an academic=20
> discipline behind this topic of which I'm ignorant. Anyway I took a=20
> first stab, attached, definitely a lot missing.
>=20
> I'm thinking we put this at ./docs/security-model.md or somewhere =
while=20
> it's a WIP. Ideally I think it ends up in docs/manual too when we're=20=

> happy with it, but we probably need to keep a canonical version in=20
> markdown for the LLMs, so there's another problem to solve.
>=20
> Thoughts? (I only started using RFC 2119-style MUST/SHOULD half way=20
> through editing so it's not consistent on that style)
>=20
> Regards, Joe
> <security-model.md>

=E2=80=94=20
Rich Bowen
[email protected]