)]}'
{
  "commit": "e4f810bc8b12ddefa8445ba0bcd4ce0170a0c21e",
  "tree": "b3dc4c8a9865ecc2083b90ff9e6d10f0eeaceee0",
  "parents": [
    "58d84b2dbc5303fc1ddd6e3c1202ceb9472256e0"
  ],
  "author": {
    "name": "Jarek Potiuk",
    "email": "jarek@potiuk.com",
    "time": "Mon Jul 13 10:10:25 2026 +0200"
  },
  "committer": {
    "name": "GitHub",
    "email": "noreply@github.com",
    "time": "Mon Jul 13 13:40:25 2026 +0530"
  },
  "message": "Add security-model discoverability pointer to the project-wide CloudStack threat model (#149)\n\n* Add draft project security threat-model document\n\nAdds a draft project-level security threat-model document\n(draft-THREAT-MODEL.md) at repo root, improving discoverability\nfor automated security scanners running against this repository.\nThe file follows the rubric format used by several other ASF\nprojects piloting security-model discoverability.\n\nThe \"draft-\" prefix signals this is a proposal for the PMC to\nreview, correct, or reject — not a finalised maintainer-blessed\nmodel. Every claim carries a provenance tag (documented /\ninferred / maintainer) so reviewers can see where each claim\noriginates; §14 collects open questions for the maintainers.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) \u003cnoreply@anthropic.com\u003e\n\n* Point to the project-wide CloudStack threat model instead of a per-repo copy\n\nDrop the standalone draft-THREAT-MODEL.md and wire the discoverability chain\nAGENTS.md -\u003e SECURITY.md -\u003e the project-wide model in apache/cloudstack\n(apache/cloudstack#13293), so scanners find one canonical model and this repo\ninherits it rather than duplicating it.\n\nGenerated-by: Claude Code\n\n* Exclude SECURITY.md + AGENTS.md from RAT\n\nThese scaffold files carry an SPDX license header, but this repo\u0027s Apache RAT\ncheck doesn\u0027t scan headers embedded in Markdown, so list them in .rat-excludes.\n\nGenerated-by: Claude Code\n\n* Potential fix for pull request finding\n\nCo-authored-by: Copilot Autofix powered by AI \u003c175728472+Copilot@users.noreply.github.com\u003e\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) \u003cnoreply@anthropic.com\u003e\nCo-authored-by: dahn \u003cdaan.hoogland@gmail.com\u003e\nCo-authored-by: Copilot Autofix powered by AI \u003c175728472+Copilot@users.noreply.github.com\u003e",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "623982265443b876af5fbd8270a4f06b4d63ce23",
      "old_mode": 33188,
      "old_path": ".rat-excludes",
      "new_id": "1511f97d365cd84d7e5244c3e6bc57abe6c18cee",
      "new_mode": 33188,
      "new_path": ".rat-excludes"
    },
    {
      "type": "add",
      "old_id": "0000000000000000000000000000000000000000",
      "old_mode": 0,
      "old_path": "/dev/null",
      "new_id": "5bd145bbb733658a1dc87d73078878d32871eb42",
      "new_mode": 33188,
      "new_path": "AGENTS.md"
    },
    {
      "type": "add",
      "old_id": "0000000000000000000000000000000000000000",
      "old_mode": 0,
      "old_path": "/dev/null",
      "new_id": "881a9e63d353ac1240712fdbfedb36f53bbe66d6",
      "new_mode": 33188,
      "new_path": "SECURITY.md"
    }
  ]
}
