)]}'
{
  "log": [
    {
      "commit": "2d64616086b7c754452dd68936410b8bd4604fc1",
      "tree": "c0a92caa1c88a1eb7fba50c5b7ebebf7e9a941b0",
      "parents": [
        "0a597864fea7e4ad1e5ad82e4dd6e82ec0b2bcd8",
        "08af9a60715a3bdd0d72d1adc17ef7e2f1ea9c53"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon Aug 10 19:40:40 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 10 19:40:40 2026 +0200"
      },
      "message": "Merge pull request #83 from apache/add-syncope-threat-model\n\nAdd Syncope threat model"
    },
    {
      "commit": "0a597864fea7e4ad1e5ad82e4dd6e82ec0b2bcd8",
      "tree": "fe258bb4e0addb4d2e4df29816dffdfb7a9c557d",
      "parents": [
        "bce87b22eee208198ef00966d176158f83b8ed02",
        "4e2087bc257b3085ed369a887842728745c2bae4"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon Aug 10 19:39:54 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 10 19:39:54 2026 +0200"
      },
      "message": "Merge pull request #82 from apache/cve-updates-2026-08-10\n\nCVE updates from 2026-08-03 through 2026-08-10"
    },
    {
      "commit": "08af9a60715a3bdd0d72d1adc17ef7e2f1ea9c53",
      "tree": "c0a92caa1c88a1eb7fba50c5b7ebebf7e9a941b0",
      "parents": [
        "4e2087bc257b3085ed369a887842728745c2bae4"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Aug 10 19:11:34 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Aug 10 19:11:34 2026 +0200"
      },
      "message": "Add Syncope threat model\n\nApache Syncope has no dedicated security page yet, but the reference\nguide\u0027s \"REST Authorization Summary\" describes how its RESTful services\nare partitioned by the authentication and authorization they require:\nanonymous endpoints, endpoints gated by the shared anonymous key,\nself-service endpoints requiring authentication, and administrative\nendpoints requiring entitlements granted through roles.\n\nThat is the closest thing the project currently documents to a threat\nmodel, so link it until the PMC publishes something better.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "4e2087bc257b3085ed369a887842728745c2bae4",
      "tree": "fe258bb4e0addb4d2e4df29816dffdfb7a9c557d",
      "parents": [
        "81f992e1004d8c7b7505c45514e22d7552ed8f4b"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Aug 10 19:07:49 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Aug 10 19:07:49 2026 +0200"
      },
      "message": "CVE updates from 2026-08-03 through 2026-08-10\n\nRegenerates the project pages with CVEs disclosed between 2026-08-03 and\n2026-08-10: 72 new advisories across 12 projects (CVE and OSV JSON files\nplus regenerated project pages).\n\nNew advisories: qpid (24), cxf (12), ranger (10), answer (6), apr (5),\nnifi (4), lucy (4), fory (3), jena (1), polaris (1), iotdb (1),\ntapestry (1). Lucy and Qpid get their first advisory pages.\n\nRanger CVE-2026-32227 has no OSV file: cve2osv.py does not yet support\nexplicitly \u0027unaffected\u0027 version ranges, as with the 45 advisories already\nin that situation.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "81f992e1004d8c7b7505c45514e22d7552ed8f4b",
      "tree": "a2f4bef568b790f4879471e408c9ad34ee03949a",
      "parents": [
        "c2490da2b20e8d49c969328c358486ef789a2a46"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Aug 10 19:07:34 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Aug 10 19:07:34 2026 +0200"
      },
      "message": "Add coordinates for 24 podlings, mark BifroMQ and Seata incubating\n\nFills the gaps reported by the new missing-coordinates warning: amoro,\nauron, burr, caldera, casbin, cloudberry, fesod, fluss, geaflow, graphar,\nhamilton, iggy, kie, openserverless, ossie, otava, ozhera, pegasus,\nponymail, pouchdb, resilientdb, texera, toree and xtable. Most report to\nsecurity@apache.org and publish no security model yet; cloudberry, fluss,\nhamilton, iggy and texera have their own links.\n\nAlso renames BifroMQ and Seata to \"(Incubating)\", matching their current\nstatus.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "c2490da2b20e8d49c969328c358486ef789a2a46",
      "tree": "bb2dde0a961aca126dff240c107c3be05d05e96a",
      "parents": [
        "bce87b22eee208198ef00966d176158f83b8ed02"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Aug 10 19:07:25 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Aug 10 19:07:25 2026 +0200"
      },
      "message": "Warn about projects missing security coordinates\n\nA project only appears on the overview page when project-coordinates.json\nhas an entry for it, so a newly created PMC or podling silently stays off\nthe site until someone notices. Print the list of committees without\ncoordinates at generation time, skipping retired committees and the three\nthat ship no software (attic, comdev, incubator).\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "bce87b22eee208198ef00966d176158f83b8ed02",
      "tree": "16682251db1fde1168dcd1058858cd4758982df3",
      "parents": [
        "1fcf35ead9f283a5bb25762e52d7df8065b182ba"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Mon Aug 03 13:24:40 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 03 13:24:40 2026 +0200"
      },
      "message": "Add BifroMQ threat model (#81)\n\n* Add BifroMQ threat model\n\nAdds a reference to the Apache BifroMQ security model to\n`security.apache.org`, and with it the first BifroMQ entry in the\nprojects overview.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n\n* Regenerate project pages\n\nPicks up the current CVE feed and project metadata:\n\n* Fluss has graduated, so it is no longer listed as \"(Incubating)\".\n* Refreshed \"last updated\" stamps on three Thrift advisories.\n* Drops CVE-2026-66713 from the Axis page. The record is still\n  PUBLISHED at MITRE, but it is no longer present in\n  https://cveprocess.apache.org/publicjson, which is what these pages\n  are generated from.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "1fcf35ead9f283a5bb25762e52d7df8065b182ba",
      "tree": "b2c6d06d7ddb64e8774b1b02e2894b9fb63dcbd6",
      "parents": [
        "baf3bc1af94f80bbfd2cce90e0ece9a6f54a998c"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Mon Aug 03 12:40:17 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 03 12:40:17 2026 +0200"
      },
      "message": "Delete head branches after a PR is merged (#80)\n\nMerged PR branches currently linger in the repository. Enable\n`github.pull_requests.del_branch_on_merge` so GitHub removes them\nautomatically.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "baf3bc1af94f80bbfd2cce90e0ece9a6f54a998c",
      "tree": "e67ceb043adf283effb42975773b929d90fd437f",
      "parents": [
        "d300ee10da81b990ce01e32006c1ae5678771091"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Mon Aug 03 12:31:19 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 03 12:31:19 2026 +0200"
      },
      "message": "Send repository notifications to commits@security.apache.org (#79)\n\nThe `private@security.apache.org` list is for confidential traffic; the\nnew `commits@security.apache.org` list is the right target for\nrepository events on this public repo. Also adds the `jobs` scheme so\nbuild notifications land in the same place.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "d300ee10da81b990ce01e32006c1ae5678771091",
      "tree": "8d444921220b31b47e1fd80d109aabc430607ad5",
      "parents": [
        "def829caa6d942b19cb171d584a7f9d6f4499f4e"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Fri Jul 31 13:08:18 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 31 13:08:18 2026 +0200"
      },
      "message": "CVE updates from 2026-07-30 through 2026-07-31 (#78)\n\n* CVE updates from 2026-07-30 through 2026-07-31\n\nRegenerates the project pages with CVEs disclosed on 2026-07-30 and\n2026-07-31: 16 new advisories across 6 projects (CVE and OSV JSON files\nplus regenerated project pages).\n\nAssisted-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e\n\n* cve2osv: tolerate references without tags\n\nCVE records may contain references that have no tags field. The\nconverter crashed with a KeyError on such records, so their OSV files\nwere never generated or updated. Treat a missing tags field as an empty\ntag list.\n\nAssisted-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e\n\n* Regenerate OSV files previously blocked by untagged references\n\nThe cve2osv fix allows 29 advisories to convert to OSV format for the\nfirst time (including JSPWiki CVE-2026-28811 and Zeppelin\nCVE-2026-44617 from this batch) and refreshes 6 stale OSV files whose\nCVE records had gained untagged references since their last successful\nconversion. Project pages gain the corresponding OSV json links.\n\nAssisted-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "def829caa6d942b19cb171d584a7f9d6f4499f4e",
      "tree": "6a0d8feddeeca5efb103c9018e519308acd369c2",
      "parents": [
        "46dffe9efd924b13369fa2f5426705276b72be1f"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Fri Jul 31 12:33:06 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 31 12:33:06 2026 +0200"
      },
      "message": "Add Calcite threat model (#75)\n\nAdds a reference to Calcite threat model to `security.apache.org`."
    },
    {
      "commit": "46dffe9efd924b13369fa2f5426705276b72be1f",
      "tree": "216412a53f41d4926351ef1719a2cf69adf9ba0d",
      "parents": [
        "fb3ba8c2e23788bd9ddca1e51021b698c28d63c1"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed Jul 29 20:24:47 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 29 20:24:47 2026 +0200"
      },
      "message": "Clarify reporting instructions in report-code.md (#76)\n\nRestructure the introduction so that reporters can more easily find:\n\n- the three requirements for using the security contacts (a security\n  vulnerability, undisclosed, in an ASF project), each with guidance\n  for common mistakes such as forwarding scanner findings about\n  already published CVEs,\n- the address to send the report to (per-project address listed on\n  /projects, with security@apache.org as fallback),\n- the formal requirements of report emails, including the [SECURITY]\n  subject prefix that matches the spam filter exclusion rule.\n\nThe text is reformatted using semantic line breaks.\n\nAssisted-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "fb3ba8c2e23788bd9ddca1e51021b698c28d63c1",
      "tree": "fb3c97a3cdcba06d76b98875249c072480a0b275",
      "parents": [
        "63540028f9cee5b6a522752aafcc2be86fab6955"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed Jul 29 20:22:53 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 29 20:22:53 2026 +0200"
      },
      "message": "CVE updates from 2026-07-27 through 2026-07-29 (#77)\n\nAssisted-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "63540028f9cee5b6a522752aafcc2be86fab6955",
      "tree": "ee82ac60d845a969bb30913a5f1087eb62cf3f92",
      "parents": [
        "a052793d80f921382ec3024871d79da653792ee6"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Jul 27 08:49:36 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Jul 27 08:49:36 2026 +0200"
      },
      "message": "Fix disclosure order\n"
    },
    {
      "commit": "a052793d80f921382ec3024871d79da653792ee6",
      "tree": "83bdf3f846e9fbd456fc6746935b136c4e525e11",
      "parents": [
        "035c6539628628403bd3518d5e04b43f9ecc7007"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Jul 27 07:57:48 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Jul 27 07:57:48 2026 +0200"
      },
      "message": "Threat model and CVE updates up to 2026-07-26\n"
    },
    {
      "commit": "035c6539628628403bd3518d5e04b43f9ecc7007",
      "tree": "74a0b97d6633edfbce074eaa6ca919dbd2186346",
      "parents": [
        "1ec2440bfd8f47ff50026ffcb22c3a5db913e2af"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Mon Jul 27 07:51:00 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 27 07:51:00 2026 +0200"
      },
      "message": "Add and correct verified threat-model links in project-coordinates.json (#74)\n\n* Add and correct verified threat-model links in project-coordinates.json\n\nPopulate and correct security_model_link / security_model_source for 66\nPMCs whose threat models the ASF Security team has verified, and add\nCommons-style projects[] arrays for 9 multi-repo PMCs (axis, freemarker,\ngrails, jackrabbit, polaris, superset, teaclave, trafficserver, ws).\n\nEvery URL was deterministically verified to resolve: 72 GitHub files via\nthe contents API and 9 project-site pages. This fixes several stale\nentries that pointed at GitHub\u0027s /security/policy tab or non-existent\npaths (e.g. apisix pointed at a root THREAT_MODEL.md that does not exist;\nits model lives under docs/en/latest/). Adds advisory_link: null to the\ncamel entry to satisfy the schema.\n\nGenerated-by: Claude Opus 4.8 (1M context)\n\n* Use short branch form in raw.githubusercontent.com source URLs\n\nStrip the redundant refs/heads/ segment from all security_model_source\nlinks, as requested in PR #74 review. All 87 raw URLs in the file were\nverified to still resolve with HTTP 200.\n\nAssisted-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e\n\n* Restore rendered website link for the Camel security model\n\nPoint security_model_link back at camel.apache.org as requested in\nPR #74 review; the GitHub source stays in security_model_source.\nThe rendered page was verified to resolve with HTTP 200.\n\nAssisted-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e\n\n* Link the security/policy tab whenever the model is SECURITY.md\n\nWhen security_model_source is the repository\u0027s SECURITY.md on its\ndefault branch, point security_model_link at the GitHub security/policy\ntab, which renders the same file more cleanly. Converts 13 blob links\n(fineract, freemarker, impala, parquet-java, pdfbox, superset, tomee,\ntrafficserver and the axis, freemarker and trafficserver sub-projects);\nbaremaps, hadoop, httpd, paimon and pulsar already followed this\nconvention. Each source branch was checked to be the repository default\nand all 18 policy pages resolve with HTTP 200.\n\nAssisted-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e\n\n* Move WSS4J threat model into the ws projects list\n\nWSS4J is one of the projects under the Web Services PMC, so its threat\nmodel belongs in the projects array next to Axiom, XmlSchema and\nNeethi rather than at the PMC level, as noted in PR #74 review. The\nURLs are unchanged.\n\nAssisted-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e\n\n* Add the Apache Knox threat model\n\nKnox documents its threat model in THREAT_MODEL.md on the default\nbranch; the raw URL was verified to resolve with HTTP 200.\n\nAssisted-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e\n\n---------\n\nCo-authored-by: Piotr P. Karwasz \u003cpiotr@github.copernik.eu\u003e"
    },
    {
      "commit": "1ec2440bfd8f47ff50026ffcb22c3a5db913e2af",
      "tree": "bfe81f4e822b9dc0ba3c282cda828818b4a672d3",
      "parents": [
        "688b49dd77e12d8bea3c3d690f69122f8f07c16a"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Tue Jul 21 13:14:12 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Tue Jul 21 13:14:12 2026 +0200"
      },
      "message": "2026-07-21 CVE updates\n"
    },
    {
      "commit": "688b49dd77e12d8bea3c3d690f69122f8f07c16a",
      "tree": "ea4a8d5d615e47a05e45c6180b9d69bf8f3d75a3",
      "parents": [
        "be7765efeaa2f3d6a6239a6c0d056e9d8f5c6c6e",
        "db30e1acb377a668955529179bcf20e51285c2ec"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Sun Jul 19 01:01:58 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 19 01:01:58 2026 +0100"
      },
      "message": "Merge pull request #62 from oscerd/camel-advisories-link\n\nAdd security advisories link for Apache Camel"
    },
    {
      "commit": "db30e1acb377a668955529179bcf20e51285c2ec",
      "tree": "ea4a8d5d615e47a05e45c6180b9d69bf8f3d75a3",
      "parents": [
        "987fb519f4a944bd4376b725c50aa09c2694f50e",
        "be7765efeaa2f3d6a6239a6c0d056e9d8f5c6c6e"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Sun Jul 19 01:01:49 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 19 01:01:49 2026 +0100"
      },
      "message": "Merge branch \u0027main\u0027 into camel-advisories-link"
    },
    {
      "commit": "be7765efeaa2f3d6a6239a6c0d056e9d8f5c6c6e",
      "tree": "e254796190daa893bc29351b01e62490348c1399",
      "parents": [
        "c69c1dfc2219fd5140ab8d7fc0a2f224d58efb3b",
        "12373cb4cf2a7e41f54708820c4689d7b1aaf6a3"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Sun Jul 19 00:17:58 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Sun Jul 19 00:17:58 2026 +0200"
      },
      "message": "Merge remote-tracking branch \u0027apache/cve-updates-2026-07-17\u0027\n"
    },
    {
      "commit": "12373cb4cf2a7e41f54708820c4689d7b1aaf6a3",
      "tree": "e254796190daa893bc29351b01e62490348c1399",
      "parents": [
        "cf40c2bf16ee9314cd57a40ad23b98cbc900528a",
        "a081bb94ba157bfe25ad0617fde9e9aa98960e95"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Sat Jul 18 21:28:11 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 18 21:28:11 2026 +0100"
      },
      "message": "Merge pull request #73 from apache/pmc-projects-schema\n\nSupport PMCs that ship multiple projects (Apache Commons example)"
    },
    {
      "commit": "a081bb94ba157bfe25ad0617fde9e9aa98960e95",
      "tree": "e254796190daa893bc29351b01e62490348c1399",
      "parents": [
        "a793683ee7e07e7279e654f5da1c9b7450f89c91"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Sat Jul 18 19:58:08 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Sat Jul 18 19:58:08 2026 +0200"
      },
      "message": "Regenerate project pages for simplified mail subject\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "a793683ee7e07e7279e654f5da1c9b7450f89c91",
      "tree": "261e7035ca5b2a6bb324d3976db1f1e43ca0fa8a",
      "parents": [
        "c328b906968c9b912ee645d90d8c5d168b048699"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Sat Jul 18 19:58:07 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Sat Jul 18 19:58:07 2026 +0200"
      },
      "message": "Simplify mailto subject to bare project name\n\nDrop the \u0027[FINDING]\u0027 tag and the redundant \u0027Apache \u0027 prefix from the\nprefilled mail subject, so reporting Apache Accumulo yields subject\n\u0027Accumulo\u0027 instead of \u0027[FINDING] Apache Accumulo\u0027. Reuse the existing\ndisplay_name() helper rather than a bespoke word-stripper.\n\nSuggested-by: Arnout Engelen\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "c328b906968c9b912ee645d90d8c5d168b048699",
      "tree": "afd0e89f4839ce7c9e84b91da74babf7d6dfe3c3",
      "parents": [
        "e2da45b6264ce744b25e229afcf345709c5a9bfe"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 23:12:35 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 23:12:35 2026 +0200"
      },
      "message": "Regenerate project pages for Commons security models\n\nRebuild the overview and per-project pages so each security model is\nlisted under a \u0027Security model(s)\u0027 heading, including the Commons PMC\nand its per-project models.\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "e2da45b6264ce744b25e229afcf345709c5a9bfe",
      "tree": "36b0b2e2bdc76d0b0490a4bf7a44a53ab19adc17",
      "parents": [
        "88c8144cc3674654a9354c4011551333f7fe0f17"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 23:05:34 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 23:05:34 2026 +0200"
      },
      "message": "Register Apache Commons multi-project security models\n\nUse Apache Commons as the first example of a PMC that ships several\nprojects. Point the Commons entry at its new umbrella threat model\n(commons.apache.org/threat_model.html, sourced from the cms-site SVN)\nrather than the older CVE-listing security page, and list the Commons\ncomponents that publish a threat model of their own:\n\n  - Apache Commons Configuration\n  - Apache Commons Imaging\n  - Apache Commons XML\n\nThese are the proper Commons components whose security pages describe\ncomponent-specific security properties (what untrusted input is and is\nnot expected to be safe). Components that only list CVEs or defer to the\nglobal Commons security page are left out.\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "88c8144cc3674654a9354c4011551333f7fe0f17",
      "tree": "c3ae4e2a9a5d369cf096749a32acef504edcc45c",
      "parents": [
        "cf40c2bf16ee9314cd57a40ad23b98cbc900528a"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 13:28:03 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 22:51:52 2026 +0200"
      },
      "message": "Support PMCs that ship multiple projects\n\nSome PMCs maintain more than one project, each with its own security\nmodel. Rename the schema\u0027s \"project\" def to \"pmc\" and introduce a new\n\"project\" def holding the three fields a named piece of software needs:\nname, security_model_link and security_model_source. A \"pmc\" extends\n\"project\" and gains an optional \"projects\" list for the individual\nprojects it ships.\n\nThe extension uses allOf, so the closure keyword had to change from\n\"additionalProperties\": false to \"unevaluatedProperties\": false:\nadditionalProperties only considers the properties declared next to it\nand would reject the keys a \"pmc\" adds on top of \"project\".\n\nproject-page.py now renders every security_model_link (the PMC\u0027s own\nplus one per project) as a list of links, each labelled\n\"\u003cname\u003e security model\".\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "c69c1dfc2219fd5140ab8d7fc0a2f224d58efb3b",
      "tree": "421b182691d3d21ea7efd941d366fb9e2b0eac96",
      "parents": [
        "c90027ce420fd48e050734728cf6e01bebd20d77",
        "cf40c2bf16ee9314cd57a40ad23b98cbc900528a"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Fri Jul 17 21:15:08 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 21:15:08 2026 +0100"
      },
      "message": "Merge pull request #72 from apache/cve-updates-2026-07-17\n\n2026-07-17 CVE updates"
    },
    {
      "commit": "cf40c2bf16ee9314cd57a40ad23b98cbc900528a",
      "tree": "421b182691d3d21ea7efd941d366fb9e2b0eac96",
      "parents": [
        "c90027ce420fd48e050734728cf6e01bebd20d77"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 21:37:01 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 21:37:01 2026 +0200"
      },
      "message": "2026-07-17 CVE updates\n\nRegenerate project pages against a freshly fetched advisory index\n(cveprocess.apache.org/publicjson). Adds 17 new advisories across\naccumulo, airflow, ant, doris, fineract, gravitino, kylin, logging,\nopenmeetings and tomcat, refreshes enriched airflow CVE records, and\npublishes the security-page links for the threat models registered\nsince the last regeneration.\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "c90027ce420fd48e050734728cf6e01bebd20d77",
      "tree": "724b1be04ef6f818eb1d7570172c34b349dc8328",
      "parents": [
        "a9d9355f68d69e4024e15f020675b4e155ad26ec"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 14:39:54 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 14:39:54 2026 +0200"
      },
      "message": "Register security models for avro, parquet, shenyu; fix cloudstack\n\nA search across coordinates, git repos, AGENTS.md chains, project\nwebsites and cwiki found three projects that publish a real threat\nmodel but had none registered, plus one entry pointing at the wrong\npage.\n\n* avro: website \"Security Model\" section (library scope: transport out\n  of scope, side-channel leakage a non-goal, supply chain a caller\n  duty).\n* parquet: SECURITY.md carries a \"Threat model\" section (untrusted\n  files, caller-imposed resource limits, class loading not itself a\n  vulnerability). Lives in parquet-java.\n* shenyu: SECURITY_MODEL.md, linked from SECURITY.md, states that all\n  authenticated Admin users are fully trusted and that RBAC is not a\n  hard security boundary.\n* cloudstack: was pointing at https://cloudstack.apache.org/security/,\n  which has a \"Security Model\" heading and operator disclaimers but no\n  trust boundary over principals. The actual model is the in-repo\n  THREAT_MODEL.md, reached via AGENTS.md -\u003e SECURITY.md, and it does\n  classify authenticated end users as untrusted.\n\nAll eight URLs verified to return 200. security_model_source uses the\nrefs/heads raw form, matching the majority convention in the file.\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "a9d9355f68d69e4024e15f020675b4e155ad26ec",
      "tree": "17d3fbc21a2b23d02270092920890c9909d26a79",
      "parents": [
        "e10e4681025bf9dc4cd4526154c316ba5fd405f4"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 11:44:57 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 17 11:45:17 2026 +0200"
      },
      "message": "Update threat models\n\nThis commit updates threat model links for the benefit of tools that read `project-coordinates.json`.\n\nAn update to the website will be submitted via PR instead of a direct commit, so it can be reviewed.\n"
    },
    {
      "commit": "e10e4681025bf9dc4cd4526154c316ba5fd405f4",
      "tree": "7cd6adca8d5bbceb8ae2156fc675eefa48e05a5e",
      "parents": [
        "954fe39363273e34cdcead87424a63d04719152f"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Jul 15 12:24:33 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Jul 15 12:24:33 2026 +0200"
      },
      "message": "data update\n"
    },
    {
      "commit": "987fb519f4a944bd4376b725c50aa09c2694f50e",
      "tree": "85f57768f2ff29d3921988674a6669821ad06b7d",
      "parents": [
        "954fe39363273e34cdcead87424a63d04719152f"
      ],
      "author": {
        "name": "Andrea Cosentino",
        "email": "ancosen@gmail.com",
        "time": "Thu Jun 11 10:53:39 2026 +0200"
      },
      "committer": {
        "name": "Andrea Cosentino",
        "email": "ancosen@gmail.com",
        "time": "Mon Jul 13 09:59:33 2026 +0200"
      },
      "message": "Add security advisories link for Apache Camel\n\nUpdate project-coordinates.json instead of the generated _index.md.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "954fe39363273e34cdcead87424a63d04719152f",
      "tree": "34a4fb666062b06f6b6c064a287747ed0b6c169c",
      "parents": [
        "2ef345f6a953048dc4af294286f1dd6146851290"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 10 11:14:14 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Fri Jul 10 11:14:14 2026 +0200"
      },
      "message": "2026-07-10 CVE updates\n"
    },
    {
      "commit": "2ef345f6a953048dc4af294286f1dd6146851290",
      "tree": "46569d9eecdc6fb055221a32993a788559be9d5b",
      "parents": [
        "0a551a90e97215ba42a2e9ae4635784abb6f3173"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed Jul 08 18:41:33 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 08 18:41:33 2026 +0200"
      },
      "message": "Refactor project-coordinates: security_model_link and AI-friendly sources (#69)\n\nRename the \"link\" field to \"security_model_link\" and add a\n\"security_model_source\" field that points at an AI-friendly plain-text\n(raw GitHub) version of the security page. The source is not rendered on\nthe site; it is there for external tooling.\n\n- Add project-coordinates.schema.json (JSON Schema; the six core fields\n  are required) and reference it from the data file via a \"$schema\" key.\n  The page generator now skips \"$\"-prefixed meta keys.\n- Normalize every entry to carry the six core fields (null when absent);\n  default the one missing contact to security@apache.org.\n- Fill security_model_source from raw.githubusercontent.com for\n  GitHub-hosted security pages.\n- Normalize GitHub SECURITY.md entries to the canonical /security/policy\n  human link, with the raw SECURITY.md as the source.\n- Regenerate the affected overview and project pages.\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "0a551a90e97215ba42a2e9ae4635784abb6f3173",
      "tree": "2d1c5ca0d42d345aef72a1aad8b1c120c52a4b48",
      "parents": [
        "7005d861497149ece4fc7ceb36dc91b157f1c718"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Tue Jul 07 13:10:52 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 07 13:10:52 2026 +0200"
      },
      "message": "Regenerate Apache Airflow advisories from refreshed publicjson (#70)\n\nAdds five new Airflow advisories (CVE-2026-48828, CVE-2026-48891,\nCVE-2026-48892, CVE-2026-49296, CVE-2026-49487) and refreshes\nCVE-2026-41016. No advisories were removed.\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "7005d861497149ece4fc7ceb36dc91b157f1c718",
      "tree": "f70e87f1e01c71d9171ef7a1a6f97c9980d2da92",
      "parents": [
        "17f9cde379d79aef011a751f221901fcd69178c8"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue Jul 07 10:27:21 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue Jul 07 10:27:21 2026 +0200"
      },
      "message": "various updates\n"
    },
    {
      "commit": "17f9cde379d79aef011a751f221901fcd69178c8",
      "tree": "018fe1ac85d7cafae5bb7d6acb62afcd6791367d",
      "parents": [
        "d154def5f42e127c0a5fa39d6be2401c5b3cf01e"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Mon Jul 06 16:37:57 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 16:37:57 2026 +0200"
      },
      "message": "Tabbed projects overview with logos and per-project advisories (#68)\n\n* Turn projects overview into alphabetical tabbed page\n\nRework the /projects overview into a Ponymail-style page with A-Z letter\ntabs. Each project is a card listing a required security contact plus\noptional security page and advisory links.\n\n- scripts/project-page.py: generate the tab HTML wrapper (container, nav,\n  buttons) with Markdown sections and lists inside each panel. Security\n  contact is emitted first for stable ordering, as a standard mailto with\n  a prefilled subject ([FINDING] for project lists, [FINDING] \u003cproject\u003e\n  for the shared Security Team list). Link text is the bare address.\n- themes/kube/static/css/custom.css: documented, scoped styles for the tab\n  bar, folder-tab active state, and a responsive card grid.\n- themes/kube/static/js/main.js: vanilla tab switching with #letter-X\n  deep links and no-JS fallback (all panels visible).\n- content/projects/_index.md: regenerated output.\n\nAssisted-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n\n* Add project logos and always-on experimental advisories link\n\n- project-coordinates.json: add optional logo_link field, populated for\n  the projects that publish https://www.apache.org/logos/res/\u003cpmc\u003e/\n  default.png. Kept hand-maintained so the build stays offline. Also drop\n  the \"incubator\" entry, which is not a project.\n- project-page.py: render the logo as a right-floated \u003cimg\u003e in each card\n  when logo_link is set; link the generated per-project page at\n  /projects/\u003cpmc\u003e/ as \"Advisories (experimental)\" when we hold advisories\n  for it; and give the generic Security Team mailto a [FINDING] subject.\n- content/projects/_index.md: regenerated output.\n\nAssisted-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n\n* Restore ~4 column project grid, cap logo at half the card\n\nNarrow the card grid back to minmax(320px, 1fr) (roughly 4 columns on a\nwide screen) now that the right-floated logo fills the gutter the two-line\nlabels leave. Cap .project-logo at max-width:50% so the logo never takes\nmore than half a card and the text always keeps the other half.\n\nAssisted-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n\n* Show \"none so far\" for projects without advisories\n\nA per-project page is only generated when we hold advisories for a\nproject, so projects with none had no advisories line at all. Keep the\n\"Advisories (experimental)\" label for a uniform card and show the\nplaceholder \"none so far\" instead of a link that would 404.\n\nAssisted-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "d154def5f42e127c0a5fa39d6be2401c5b3cf01e",
      "tree": "76faf0ce84fbb518ae9fdc41a0091145c3947331",
      "parents": [
        "81abf5a454e1f403b3d652d0b281c5ef77360dd2"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Jul 06 16:17:18 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Mon Jul 06 16:17:18 2026 +0200"
      },
      "message": "Sort keys in `project-coordinates.json`\n"
    },
    {
      "commit": "81abf5a454e1f403b3d652d0b281c5ef77360dd2",
      "tree": "9b6988f1f7ab11070d2aec30f9f150fbb66a4fdb",
      "parents": [
        "6357fd6c46daa227fd56a7d7745769ad7590c317"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Thu Jul 02 12:57:59 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 02 12:57:59 2026 +0200"
      },
      "message": "Add Apache Jena threat model link (#66)\n\nAdd a jena entry to project-coordinates.json pointing at the project\u0027s\nTHREAT_MODEL.md, and regenerate the project pages.\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "6357fd6c46daa227fd56a7d7745769ad7590c317",
      "tree": "8312c6af842d3f2fbe3bbbdcf65bf3cb3d342625",
      "parents": [
        "9f41bc9652ed1aa8a11936812deb3e24cc22758e"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jul 02 12:56:56 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jul 02 12:57:13 2026 +0200"
      },
      "message": "Revert \"Complete project-coordinates.json with all PMCs from committees.json\"\n\nAccidentally pushed to the main branch, doesn\u0027t make sense to list\ncommittees for which we don\u0027t have particular information.\n\nThis reverts commit 9f41bc9652ed1aa8a11936812deb3e24cc22758e.\n"
    },
    {
      "commit": "9f41bc9652ed1aa8a11936812deb3e24cc22758e",
      "tree": "95e49678b7dfd389ca4598f39a006a9b7cee1a5b",
      "parents": [
        "3eca6076091046ecccd7f111e2a14e5c20a1c53e"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Thu Jul 02 11:14:51 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Thu Jul 02 11:14:51 2026 +0200"
      },
      "message": "Complete project-coordinates.json with all PMCs from committees.json\n\nAdd stub coordinate entries for the 116 PMCs present in committees.json\nbut missing from project-coordinates.json, using the project name from\ncommittees.json with a null security page and the foundation-wide\nsecurity@apache.org contact. Keys are now kept alphabetically sorted.\n\nRegenerating the pages also picked up new advisories as a side effect:\n- Apache Gravitino: CVE-2025-53648\n- Apache HttpComponents: CVE-2026-54399, CVE-2026-54428\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "3eca6076091046ecccd7f111e2a14e5c20a1c53e",
      "tree": "8312c6af842d3f2fbe3bbbdcf65bf3cb3d342625",
      "parents": [
        "56fd5bc2a8ce562408fac4a7e4e1c9668cc362bb"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed Jul 01 01:04:56 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 01 01:04:56 2026 +0200"
      },
      "message": "Update CVE records (#64)\n\n* Update CVE records\n\nRegenerate the project security pages from the latest advisory data\n(scripts/project-page.py).\n\n- Add 174 new CVE records (.cve.json / .osv.json) across 21 projects,\n  including a new Apache Cordova project page.\n- Refresh existing CVE records and the per-project advisory pages.\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n\n* Ignore fetched scripts/projects.xml\n\nprojects.xml is downloaded by scripts/fetch-data.sh and is not part of\nthe site sources.\n\nAssisted-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "56fd5bc2a8ce562408fac4a7e4e1c9668cc362bb",
      "tree": "43867c374898442d6597ffa498502df71f57d5dd",
      "parents": [
        "0df4e75d9630360a5fc2f0c649681dc6d9a33cb5"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Tue Jun 30 13:37:07 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "piotr@github.copernik.eu",
        "time": "Tue Jun 30 13:37:26 2026 +0200"
      },
      "message": "Add IDEA folder to gitignore\n"
    },
    {
      "commit": "0df4e75d9630360a5fc2f0c649681dc6d9a33cb5",
      "tree": "4f8cf05a2225c29c6a0d6dfbc09d1480e1ec6a50",
      "parents": [
        "7709bc58d24d3d2381eaf7dffc4c69697b945845"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 26 10:36:13 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 26 10:36:13 2026 +0200"
      },
      "message": "contributing link for seatunnel\n"
    },
    {
      "commit": "7709bc58d24d3d2381eaf7dffc4c69697b945845",
      "tree": "5035bd2359978f57575815dc15a28a06b1cc9c65",
      "parents": [
        "ae1c5150be16829712ca0e7542fca5cbebd7662f"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 26 10:24:58 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 26 10:24:58 2026 +0200"
      },
      "message": "artemis security model\n"
    },
    {
      "commit": "ae1c5150be16829712ca0e7542fca5cbebd7662f",
      "tree": "952275a3e59ae30883257b0bdf81d9c8df9eb4a9",
      "parents": [
        "3338fc27e56895d27a26579c4acf3851cebb8cec"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 22 11:53:42 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 22 11:53:42 2026 +0200"
      },
      "message": "Add OpenDAL security model\n"
    },
    {
      "commit": "3338fc27e56895d27a26579c4acf3851cebb8cec",
      "tree": "6f89ece2b3190f4dc5b1b4fd1cd03c81469d40ce",
      "parents": [
        "1fb15980303d7007c87df6dbfee24204be2187af"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 22 11:42:35 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 22 11:42:35 2026 +0200"
      },
      "message": "Paimon security model\n"
    },
    {
      "commit": "1fb15980303d7007c87df6dbfee24204be2187af",
      "tree": "736ab0092baca591b9fe120aa04c36139043d07c",
      "parents": [
        "de7aa7d2e261b28522955dec8cc910f1ccf028a1"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue Jun 16 14:22:54 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue Jun 16 14:22:54 2026 +0200"
      },
      "message": "httpd security model\n"
    },
    {
      "commit": "de7aa7d2e261b28522955dec8cc910f1ccf028a1",
      "tree": "e7b270be1a687c25550b300f90492e0d574f840d",
      "parents": [
        "ad14a84b1c0d44d35f4c566377d5e4815290462e"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue Jun 16 10:33:42 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue Jun 16 10:33:42 2026 +0200"
      },
      "message": "Thrift security model\n"
    },
    {
      "commit": "ad14a84b1c0d44d35f4c566377d5e4815290462e",
      "tree": "f8f6cddf31a01da46a63e3bb3193043ea59c5433",
      "parents": [
        "09d016f460b5c5627d7b9c66742197b3e67ecf8a"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jun 11 13:48:32 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jun 11 13:48:32 2026 +0200"
      },
      "message": "httpcomponents coordinates key\n"
    },
    {
      "commit": "09d016f460b5c5627d7b9c66742197b3e67ecf8a",
      "tree": "88ef366d334d735c4e497cefa9cba8e3dd56c420",
      "parents": [
        "0aea5707e007b1ec86895b0e1f72cc50458b352f"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jun 11 11:09:49 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jun 11 11:09:49 2026 +0200"
      },
      "message": "iceberg contributing link\n"
    },
    {
      "commit": "0aea5707e007b1ec86895b0e1f72cc50458b352f",
      "tree": "e91f846f1b49beaa52e4acd0595b370e9fe41125",
      "parents": [
        "1edd6b717180f0c82b6fc97cc66ac4895f8fa83a"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Jun 10 16:22:04 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Jun 10 16:22:04 2026 +0200"
      },
      "message": "kyuubi security list\n"
    },
    {
      "commit": "1edd6b717180f0c82b6fc97cc66ac4895f8fa83a",
      "tree": "8963a970f1e7f4bf0848bfd23cc5d90c52d0e291",
      "parents": [
        "0c31f31335df918414e3465b53eb4f4757e6efb6"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Jun 10 11:37:41 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Jun 10 11:37:41 2026 +0200"
      },
      "message": "Impala security model\n"
    },
    {
      "commit": "0c31f31335df918414e3465b53eb4f4757e6efb6",
      "tree": "0d2b73e392bc18628d0efba3f4d3a0840566119e",
      "parents": [
        "103a974b6f7107deec6a944825d0d81ee2c3b91c"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 08 12:30:17 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 08 12:30:17 2026 +0200"
      },
      "message": "hbase security model\n"
    },
    {
      "commit": "103a974b6f7107deec6a944825d0d81ee2c3b91c",
      "tree": "a944e7e282d9f6ffd79022df2c15188a74e16eb9",
      "parents": [
        "2c99e9a026e76bba4db84db46306a4aea6bc01ce"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 05 10:51:07 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 05 10:51:07 2026 +0200"
      },
      "message": "bRPC security model, data update\n"
    },
    {
      "commit": "2c99e9a026e76bba4db84db46306a4aea6bc01ce",
      "tree": "6a1466b62d8d365cd2202e085049ecc7bdafe0ce",
      "parents": [
        "202a1e36b980350022564eb7b536148c114dd4ae"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 05 10:03:36 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 05 10:03:36 2026 +0200"
      },
      "message": "ozone security list\n"
    },
    {
      "commit": "202a1e36b980350022564eb7b536148c114dd4ae",
      "tree": "f85d14b769754e24cded184d0ec6ec95bf82589d",
      "parents": [
        "50e80fe64a3503507e900933fe94b399da63e7f1",
        "ea747560795aad00e2f05ad5a224456ef532d2e0"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jun 04 10:47:37 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jun 04 10:47:37 2026 +0200"
      },
      "message": "Merge remote-tracking branch \u0027origin/main\u0027\n"
    },
    {
      "commit": "50e80fe64a3503507e900933fe94b399da63e7f1",
      "tree": "850a3cf966f52ae7e0768834f5ce539309baee68",
      "parents": [
        "09dc65627739855daeb5bc6649b83ec7ec48e4eb"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jun 04 10:47:03 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jun 04 10:47:03 2026 +0200"
      },
      "message": "more updates\n"
    },
    {
      "commit": "09dc65627739855daeb5bc6649b83ec7ec48e4eb",
      "tree": "ac2dc7d0ce64267b121f9c8b3c8fc68bf1049ad6",
      "parents": [
        "da80dd08d70ba78f5daefdf98eea24f29bd3d172"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jun 04 10:45:46 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Jun 04 10:45:46 2026 +0200"
      },
      "message": "fix cassandra link\n"
    },
    {
      "commit": "ea747560795aad00e2f05ad5a224456ef532d2e0",
      "tree": "2bb1eeedde518c1025b05c1130bb177777130744",
      "parents": [
        "f05b2c9070ac27609e9a0d4f5edfb3c2e78cd13f"
      ],
      "author": {
        "name": "Mark J. Cox",
        "email": "mjc@apache.org",
        "time": "Wed Jun 03 15:12:33 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 03 16:12:33 2026 +0200"
      },
      "message": "AI likes to give us Markdown attachments which are painful and annoying. Also be more clear that we will just reject reports that have not paid attention to this rule about useless attachments. (#60)"
    },
    {
      "commit": "da80dd08d70ba78f5daefdf98eea24f29bd3d172",
      "tree": "74e93f088d63adafdb66ce209bd97201706753fa",
      "parents": [
        "f05b2c9070ac27609e9a0d4f5edfb3c2e78cd13f"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Jun 03 10:25:06 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Jun 03 10:25:06 2026 +0200"
      },
      "message": "ignite links\n"
    },
    {
      "commit": "f05b2c9070ac27609e9a0d4f5edfb3c2e78cd13f",
      "tree": "53ba14e80b1e0b6f86a288d157f26274187d00a3",
      "parents": [
        "a2d79ce33d3624886505a2fcccd754853c0858cb"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 01 15:22:49 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 01 15:22:49 2026 +0200"
      },
      "message": "pekko security model\n"
    },
    {
      "commit": "a2d79ce33d3624886505a2fcccd754853c0858cb",
      "tree": "96098fbb1772966bf57e7e1fbe6933a4e9fb2e69",
      "parents": [
        "5a1bf69508495068cc5f513a1e4f3ac58f6c67bb"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 01 15:13:01 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 01 15:13:01 2026 +0200"
      },
      "message": "cassandra: contributing\n"
    },
    {
      "commit": "5a1bf69508495068cc5f513a1e4f3ac58f6c67bb",
      "tree": "33b8780475b26c4e68b1cb5094fa14f859dedd20",
      "parents": [
        "df8e8ebe989955f49f8cfaa37caf1d83d7d5e5c1"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 01 15:02:20 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 01 15:02:20 2026 +0200"
      },
      "message": "Cassandra security model\n"
    },
    {
      "commit": "df8e8ebe989955f49f8cfaa37caf1d83d7d5e5c1",
      "tree": "f1d22486baa097d811a1682cd259a8cb244775f7",
      "parents": [
        "ec84a52167bb9ef6d627c46d4f3f894a8afffeaf"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri May 29 13:46:21 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri May 29 13:46:21 2026 +0200"
      },
      "message": "add shardingsphere contributing link\n"
    },
    {
      "commit": "ec84a52167bb9ef6d627c46d4f3f894a8afffeaf",
      "tree": "98a209ba9e4f956cd0300ba167800c28c7a8d48c",
      "parents": [
        "997650438c2d4143a680ea2e946101218d342c13"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri May 29 13:46:12 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri May 29 13:46:12 2026 +0200"
      },
      "message": "Add httpd contributing link\n"
    },
    {
      "commit": "997650438c2d4143a680ea2e946101218d342c13",
      "tree": "f60ae59d7375673de8c63b8069c8316f55391e3c",
      "parents": [
        "28d1ad66483a28552b77c1473360fcaf1106d715"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri May 29 10:54:27 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri May 29 10:54:27 2026 +0200"
      },
      "message": "iceberg list and model link\n"
    },
    {
      "commit": "28d1ad66483a28552b77c1473360fcaf1106d715",
      "tree": "390009820c1e2a5146531678f0fb3cc5be3cbbd8",
      "parents": [
        "fb11057f6e47ddb38fc7f40814d7de3da41da5dd"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 28 15:58:32 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 28 15:58:32 2026 +0200"
      },
      "message": "artemis links\n"
    },
    {
      "commit": "fb11057f6e47ddb38fc7f40814d7de3da41da5dd",
      "tree": "bea37d7718e069dc131f99e6adbe06a8b3493d6f",
      "parents": [
        "bfa173cb575c642f2691b1dec197305d59c48e7d"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 28 15:50:30 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 28 15:50:30 2026 +0200"
      },
      "message": "Maven contributing link\n"
    },
    {
      "commit": "bfa173cb575c642f2691b1dec197305d59c48e7d",
      "tree": "785d5f3731e8c7264cffdb7c6c067de097571cc1",
      "parents": [
        "a61eed6884ac361e2480a7f075f6f87666f135b1"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 28 09:22:58 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 28 09:22:58 2026 +0200"
      },
      "message": "shiro contributing link\n"
    },
    {
      "commit": "a61eed6884ac361e2480a7f075f6f87666f135b1",
      "tree": "15731dd83cabeecaac994f76e62e27a3943a1a56",
      "parents": [
        "738997caec522c510cfbd81cff0e9b9b429b3257"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 26 19:28:09 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 26 19:28:09 2026 +0200"
      },
      "message": "superset security list\n"
    },
    {
      "commit": "738997caec522c510cfbd81cff0e9b9b429b3257",
      "tree": "b4ed70507a4edfc912a0e0b6a32ce48f1d569fc4",
      "parents": [
        "a96fa57e7d11fdd3d7252b84f0f8f43ecd2c1048"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 26 19:28:02 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 26 19:28:02 2026 +0200"
      },
      "message": "hc contributing link\n"
    },
    {
      "commit": "a96fa57e7d11fdd3d7252b84f0f8f43ecd2c1048",
      "tree": "533b5fcde077845b68df1b46cd008c1cc50925bd",
      "parents": [
        "e2dfd79596eecc8ba02cdf06b8328f9bf552a428"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 26 10:15:05 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 26 10:15:05 2026 +0200"
      },
      "message": "echarts contributing link\n"
    },
    {
      "commit": "e2dfd79596eecc8ba02cdf06b8328f9bf552a428",
      "tree": "fe811d49d39c55439b0268dc47ea725a2c36b1d0",
      "parents": [
        "20e8061d892de2c3b49e606466c6a9da9aaa2867"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon May 25 12:46:21 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon May 25 12:46:21 2026 +0200"
      },
      "message": "fory and superset security models\n"
    },
    {
      "commit": "20e8061d892de2c3b49e606466c6a9da9aaa2867",
      "tree": "681a4cf78f9986df4ec3a9bf6f033b87f619c62e",
      "parents": [
        "447ccabe00320e96f2200b685ae8a68dc10c0d2c"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 21 17:48:12 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 21 17:48:12 2026 +0200"
      },
      "message": "tomcat contributing link\n"
    },
    {
      "commit": "447ccabe00320e96f2200b685ae8a68dc10c0d2c",
      "tree": "9cd48c1e1134724f04287110fa6199ff63c78809",
      "parents": [
        "69f30357251cf2bc99bbb3c9b1ceaa3d36cd1f7b"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 21 13:54:57 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 21 13:54:57 2026 +0200"
      },
      "message": "ORC advisory link\n"
    },
    {
      "commit": "69f30357251cf2bc99bbb3c9b1ceaa3d36cd1f7b",
      "tree": "6caa979cd34a7cd617d381ca42e52db9604591b8",
      "parents": [
        "b58823eac582cd97045847e9f31560c23217f223",
        "85c176d028d2d86e431518b8fbf7389db22071fa"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 21 13:22:24 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 21 13:22:24 2026 +0200"
      },
      "message": "Merge remote-tracking branch \u0027origin/main\u0027\n"
    },
    {
      "commit": "b58823eac582cd97045847e9f31560c23217f223",
      "tree": "26db34a4ad91196db21ccb341d237a02fef9ea2b",
      "parents": [
        "f05e8d1b4a6f444b4480e732ec14873e1a1b7de3"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 21 13:21:31 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 21 13:21:31 2026 +0200"
      },
      "message": "APISIX security model\n"
    },
    {
      "commit": "f05e8d1b4a6f444b4480e732ec14873e1a1b7de3",
      "tree": "045776114669cb5aa5312e1f9d042fbc2333b302",
      "parents": [
        "8ecccdd0a298c323b4dab63fd2f3eb455f15f17e"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 21 12:54:12 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 21 12:54:12 2026 +0200"
      },
      "message": "\u0027contributing\u0027 url for spark\n"
    },
    {
      "commit": "85c176d028d2d86e431518b8fbf7389db22071fa",
      "tree": "269c4df3d6b651c5ecd6cca73958e3d193458cfe",
      "parents": [
        "8ecccdd0a298c323b4dab63fd2f3eb455f15f17e"
      ],
      "author": {
        "name": "The Apache Software Foundation",
        "email": "root-asf-gitbox-commits@apache.org",
        "time": "Thu May 21 05:36:27 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 21 12:36:27 2026 +0200"
      },
      "message": "Set up default protection ruleset for default and release branches (#58)"
    },
    {
      "commit": "8ecccdd0a298c323b4dab63fd2f3eb455f15f17e",
      "tree": "7d0aba2598621c53a234f5bdea40d12098b33100",
      "parents": [
        "e95771772e8291776135103965cafe2842a1460a"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed May 20 16:38:48 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed May 20 16:38:48 2026 +0200"
      },
      "message": "airflow contributing link\n"
    },
    {
      "commit": "e95771772e8291776135103965cafe2842a1460a",
      "tree": "3df4e377cbf20471261ec78e7be623f5440eb9c7",
      "parents": [
        "68b967a56f1541f3dadf9d7b0d14ea5739821ced"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon May 18 17:00:44 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon May 18 17:00:44 2026 +0200"
      },
      "message": "updated activemq security model\n"
    },
    {
      "commit": "68b967a56f1541f3dadf9d7b0d14ea5739821ced",
      "tree": "e1149ed8e06d8db8a06856299d506c5225ad450b",
      "parents": [
        "3e865d6a97909782903f00ecc0650f29783dacad"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Fri May 15 17:37:43 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 15 17:37:43 2026 +0200"
      },
      "message": "Replace Camel security page with security model (#57)\n\n* Replace Camel security page with security model\n\nCamel security page only contains a list of vulnerabilities, whereas linking to the security model would be more effective in reducing the number of false positives reported.\n\n* fix: add page to JSON source\n\n* fixup and regenerate\n\n---------\n\nCo-authored-by: Arnout Engelen \u003carnout@bzzt.net\u003e"
    },
    {
      "commit": "3e865d6a97909782903f00ecc0650f29783dacad",
      "tree": "a30797976e5c365e3848d2f9015c91377ff8159b",
      "parents": [
        "a1617e6f8645451514087b0d9188e718ca31067c"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri May 15 17:33:08 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri May 15 17:33:08 2026 +0200"
      },
      "message": "add pulsar contributing link\n"
    },
    {
      "commit": "a1617e6f8645451514087b0d9188e718ca31067c",
      "tree": "3787ad95ca8de8953aa9ca7f6469e387d51a3563",
      "parents": [
        "aef4caa113541a2c7ecb0509ba82e24519ecd700"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 12 11:18:13 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 12 11:18:13 2026 +0200"
      },
      "message": "hertzbeat contributing link\n"
    },
    {
      "commit": "aef4caa113541a2c7ecb0509ba82e24519ecd700",
      "tree": "957823fbd09cc5f6ded651d37b3546e7b8700a54",
      "parents": [
        "5a8b0ca234086e3986f4bb9635b775d7db99a3b7"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 07 10:22:59 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 12 11:17:38 2026 +0200"
      },
      "message": "register \u0027contributing\u0027 link for rocketmq\n"
    },
    {
      "commit": "5a8b0ca234086e3986f4bb9635b775d7db99a3b7",
      "tree": "ee4d0445370b533bcf8c650eab6ba16b308f54f8",
      "parents": [
        "985c86a25417dfe66428a18bf40c2af2c9acd2d5"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 12 10:10:36 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 12 10:11:02 2026 +0200"
      },
      "message": "airflow links\n"
    },
    {
      "commit": "985c86a25417dfe66428a18bf40c2af2c9acd2d5",
      "tree": "2053c43784a6bdaeaa672924cedb514e70ee7e7a",
      "parents": [
        "3dc602bc12b58ec413a16490964734be0471ca27"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon May 11 10:19:42 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 10:19:42 2026 +0200"
      },
      "message": "Set expectations around privacy and credits for reports (#54)\n\n* Set expectations around privacy and credits for reports\n\n* unless otherwise requested\n\n* make credit \u0027updates or additions\u0027 explicit"
    },
    {
      "commit": "3dc602bc12b58ec413a16490964734be0471ca27",
      "tree": "8467b420337a99947f59c187889586877d003eeb",
      "parents": [
        "1bc0ac4c666f5fe2cd2bc49a67a3b7d8f82aba74"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Fri May 01 13:29:49 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 01 13:29:49 2026 +0200"
      },
      "message": "huntr: mention UUID for resubmissions (#56)"
    },
    {
      "commit": "1bc0ac4c666f5fe2cd2bc49a67a3b7d8f82aba74",
      "tree": "abb1757dd09f094131b86a14cfcb72cde1c031b5",
      "parents": [
        "15ccb7366cce203647be3b3f30d96ba1de891812"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Apr 30 12:30:48 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Apr 30 12:30:48 2026 +0200"
      },
      "message": "move huntr statement out of blog\n\nsince draft posts are not actually published, so\nun-drafting but moving away so it doesn\u0027t get included\nin the blog index.\n"
    },
    {
      "commit": "15ccb7366cce203647be3b3f30d96ba1de891812",
      "tree": "48af3482171f45257e62526877445830d8a22d20",
      "parents": [
        "04cd047fd653da253dad3503cb5be2b4ceac420c"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Apr 30 12:13:20 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Apr 30 12:14:47 2026 +0200"
      },
      "message": "add favicon\n\narbitrary change to see if this will trigger the\nasf-site branch update\n"
    },
    {
      "commit": "04cd047fd653da253dad3503cb5be2b4ceac420c",
      "tree": "26b9f7e97fa431cbca79c06ce4dd40198b3226c4",
      "parents": [
        "93cc8745f21ae6f556cac931b19cefc7a66dc3ba"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Thu Apr 30 11:12:23 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 30 11:12:23 2026 +0200"
      },
      "message": "blog: no longer accepting huntr.com reports (#55)"
    },
    {
      "commit": "93cc8745f21ae6f556cac931b19cefc7a66dc3ba",
      "tree": "bf14be10b1a39f0f9409f253f0211163fd6cc17b",
      "parents": [
        "db98d83fc9339fb1898610af9ba7a0156759ec42"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Apr 23 13:04:00 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Apr 23 13:04:00 2026 +0200"
      },
      "message": "add link to selfserve list creation\n"
    },
    {
      "commit": "db98d83fc9339fb1898610af9ba7a0156759ec42",
      "tree": "4420461dead724eb00e12d831b5478732ab17fee",
      "parents": [
        "f2d251c587fe34008d19a1ded5cb8be0681fbe5b"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Apr 23 12:38:19 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Apr 23 12:38:19 2026 +0200"
      },
      "message": "link to syncope advisories\n"
    },
    {
      "commit": "f2d251c587fe34008d19a1ded5cb8be0681fbe5b",
      "tree": "932683f6afbdf267f911950db1c2b7d54fd41f96",
      "parents": [
        "cf040560c6aae1b9092ca7490e13d7d591e80c76"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue Apr 21 11:14:09 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue Apr 21 11:14:09 2026 +0200"
      },
      "message": "Add Nutch security model and CVE list\n"
    },
    {
      "commit": "cf040560c6aae1b9092ca7490e13d7d591e80c76",
      "tree": "2866f3842fa2b6782ab291500667f20eee868d88",
      "parents": [
        "38c461cef50bcdeb7fc447656b759132f9a4131b"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue Apr 14 11:18:35 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue Apr 14 11:18:35 2026 +0200"
      },
      "message": "Add Storm security model\n"
    },
    {
      "commit": "38c461cef50bcdeb7fc447656b759132f9a4131b",
      "tree": "5116fd5590368f144222c0d01b289a6df50499dd",
      "parents": [
        "d6783bd944ca089c0609a2047f3a67a5193d9f4e"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Apr 13 14:47:18 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Apr 13 14:47:36 2026 +0200"
      },
      "message": "Direct infra issues to security@infra.apache.org\n\nPer https://infra.apache.org/contact.html\n"
    },
    {
      "commit": "d6783bd944ca089c0609a2047f3a67a5193d9f4e",
      "tree": "05dba126cdf102f1f3286dad866ca5f6426c5e11",
      "parents": [
        "99e4929c22934accde4346404a57551a85c42340"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Fri Apr 10 17:51:19 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Apr 10 17:51:19 2026 +0200"
      },
      "message": "resources: add \u0027access to tools\u0027 section (#51)"
    },
    {
      "commit": "99e4929c22934accde4346404a57551a85c42340",
      "tree": "806b57fb6cce89b6a42c20aa3861f67e976e48c3",
      "parents": [
        "531ae984b77f115809ec45439da829ca83254302"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Apr 10 14:34:44 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Apr 10 14:34:44 2026 +0200"
      },
      "message": "remove test page\n"
    },
    {
      "commit": "531ae984b77f115809ec45439da829ca83254302",
      "tree": "90b68188246278a6a0792fb62d75990e61d9c7f6",
      "parents": [
        "729ea44fc408c90299dcdc406e99ca323cc1d604",
        "7088aab9b989c3335dc513867c578d7d63bda986"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Fri Apr 10 15:15:42 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Apr 10 15:15:42 2026 +0300"
      },
      "message": "Merge pull request #52 from potiuk/update-bug-bounty-programme\n\nUpdate information about bug bounty programs"
    }
  ],
  "next": "7088aab9b989c3335dc513867c578d7d63bda986"
}
