Re: [PR] Add draft threat model + SECURITY.md + AGENTS.m d for security-model discoverability [tapestry-5]

potiuk (via GitHub) <[email protected]> Wed, 17 Jun 2026 01:48:47 -0000
Newsgroups gmane.comp.jakarta.tapestry.devel
Message-ID <PR_kwDOAENlv87hErhG-52aab529-3e44-4ff7-8c0a-b374a893edb4@gitbox.apache.org>
potiuk commented on PR #61:
URL: https://github.com/apache/tapestry-5/pull/61#issuecomment-4725167685

   Thanks `thiagohp` — good catch, fixed. Broadened the exclusion from just `tapestry-core/src/test/app1` to all internal test code (`src/test/**` across every module, including `tapestry-core/src/test`), since none of it deploys. Updated §2 (component table), §3 (out-of-scope), and §11a (known non-findings) so a finding anywhere under `src/test` routes to OUT-OF-MODEL: unsupported-component.
   
   Pushed — if anything else on the model looks off, just flag it inline.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]