Skip to content

fix(docs): collapse three org-level security placeholder names into one - #1133

Open
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder
Open

fix(docs): collapse three org-level security placeholder names into one#1133
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder

Conversation

@AmirF194

Copy link
Copy Markdown
Contributor

Summary

  • The org-level advisory-admin security address had three names in the tree (<security-team-list>, <asf-security-list>, and the bare security_inbox.foundation_security_address config path) and none was registered in the placeholder table.
  • <asf-security-list> also bakes an ASF-specific name into a framework whose placeholder mechanism exists to keep adopting projects vendor-neutral.
  • Registers one org-neutral placeholder, <foundation-security-list>, and uses it at all three call sites. The distinct project-level <security-list> is untouched, since github-advisory.md's own delivery instructions deliberately address the two lists separately.

Type of change

  • Skill change (.claude/skills/<name>/) - eval fixtures updated below
  • Tool / bridge contract (tools/<system>/*.md)
  • Python package (tools/*/ with pyproject.toml)
  • Groovy reference impl
  • Cross-cutting (RFC, AGENTS.md, sandbox, privacy-LLM)
  • Documentation (docs/, README.md, CONTRIBUTING.md)
  • Project template (projects/_template/)
  • CI / dev loop (prek, workflows, validators)
  • Other:

Test plan

  • prek run --all-files not available in this environment (no uv/prek); ran the individual hooks by hand instead: tools/dev/check-placeholders.sh, npx markdownlint-cli2 and typos on both changed files, and the doctoc check (no TOC change needed; skills/** is excluded from the doctoc hook and AGENTS.md's TOC is unaffected by a text-only edit). All clean.
  • PYTHONPATH=tools/skill-and-tool-validator/src python3 -c "from skill_and_tool_validator import main; main()" (the same entry point uv run skill-and-tool-validate calls) reports the same 29 pre-existing soft warnings before and after this change, none on the touched files.
  • Other: did not run the Python test matrix; this PR touches no tools/*/ package.

RFC-AI-0004 compliance

  • HITL - any new mutation is gated on explicit user confirmation
  • Sandbox - no new unrestricted host access; network reach declared in the adapter
  • Vendor neutrality - replaces an ASF-branded placeholder (<asf-security-list>) with an org-neutral one, matching <governance-body> and <project-stage>
  • Conversational + correctable - agentic-override path documented if behaviour is adopter-tunable
  • Write-access discipline - no autonomous outbound messages; drafts only, sent on confirmation
  • Privacy LLM - private content does not reach a non-approved LLM; redactor invoked where needed

Linked issues

Fixes#1057

Notes for reviewers (optional)

Followed the naming this issue itself suggests, matching the config key: <foundation-security-list> rather than <org-security-list>. projects/_template/project.md already documents security_inbox.foundation_security_address as org-level and inherited ("Do not declare it here"), so no change was needed there.

The org-level advisory-admin security address had three names in the
tree: <security-team-list> in github-advisory.md, <asf-security-list>
(twice) in AGENTS.md, and the bare config path
security_inbox.foundation_security_address in the placeholder table,
which had no row for it at all. AGENTS.md also baked an ASF-specific
name into a framework whose placeholder mechanism exists precisely to
keep adopting projects out of that vocabulary.
Register <foundation-security-list>, sourced from
security_inbox.foundation_security_address, and use it at all three
call sites. The distinct project-level <security-list> is untouched,
since the two addresses are deliberately different in
github-advisory.md's own delivery instructions.
Fixesapache#1057
Generated-by: Claude Code (Sonnet 5)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(placeholders): the org-level security address has three names and none is registered

1 participant

@AmirF194
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(docs): collapse three org-level security placeholder names into one by AmirF194 · Pull Request #1133 · apache/magpie · GitHub
Skip to content

fix(docs): collapse three org-level security placeholder names into one - #1133

Open
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder
Open

fix(docs): collapse three org-level security placeholder names into one#1133
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder

Conversation

@AmirF194

Copy link
Copy Markdown
Contributor

Summary

  • The org-level advisory-admin security address had three names in the tree (<security-team-list>, <asf-security-list>, and the bare security_inbox.foundation_security_address config path) and none was registered in the placeholder table.
  • <asf-security-list> also bakes an ASF-specific name into a framework whose placeholder mechanism exists to keep adopting projects vendor-neutral.
  • Registers one org-neutral placeholder, <foundation-security-list>, and uses it at all three call sites. The distinct project-level <security-list> is untouched, since github-advisory.md's own delivery instructions deliberately address the two lists separately.

Type of change

  • Skill change (.claude/skills/<name>/) - eval fixtures updated below
  • Tool / bridge contract (tools/<system>/*.md)
  • Python package (tools/*/ with pyproject.toml)
  • Groovy reference impl
  • Cross-cutting (RFC, AGENTS.md, sandbox, privacy-LLM)
  • Documentation (docs/, README.md, CONTRIBUTING.md)
  • Project template (projects/_template/)
  • CI / dev loop (prek, workflows, validators)
  • Other:

Test plan

  • prek run --all-files not available in this environment (no uv/prek); ran the individual hooks by hand instead: tools/dev/check-placeholders.sh, npx markdownlint-cli2 and typos on both changed files, and the doctoc check (no TOC change needed; skills/** is excluded from the doctoc hook and AGENTS.md's TOC is unaffected by a text-only edit). All clean.
  • PYTHONPATH=tools/skill-and-tool-validator/src python3 -c "from skill_and_tool_validator import main; main()" (the same entry point uv run skill-and-tool-validate calls) reports the same 29 pre-existing soft warnings before and after this change, none on the touched files.
  • Other: did not run the Python test matrix; this PR touches no tools/*/ package.

RFC-AI-0004 compliance

  • HITL - any new mutation is gated on explicit user confirmation
  • Sandbox - no new unrestricted host access; network reach declared in the adapter
  • Vendor neutrality - replaces an ASF-branded placeholder (<asf-security-list>) with an org-neutral one, matching <governance-body> and <project-stage>
  • Conversational + correctable - agentic-override path documented if behaviour is adopter-tunable
  • Write-access discipline - no autonomous outbound messages; drafts only, sent on confirmation
  • Privacy LLM - private content does not reach a non-approved LLM; redactor invoked where needed

Linked issues

Fixes#1057

Notes for reviewers (optional)

Followed the naming this issue itself suggests, matching the config key: <foundation-security-list> rather than <org-security-list>. projects/_template/project.md already documents security_inbox.foundation_security_address as org-level and inherited ("Do not declare it here"), so no change was needed there.

The org-level advisory-admin security address had three names in the
tree: <security-team-list> in github-advisory.md, <asf-security-list>
(twice) in AGENTS.md, and the bare config path
security_inbox.foundation_security_address in the placeholder table,
which had no row for it at all. AGENTS.md also baked an ASF-specific
name into a framework whose placeholder mechanism exists precisely to
keep adopting projects out of that vocabulary.
Register <foundation-security-list>, sourced from
security_inbox.foundation_security_address, and use it at all three
call sites. The distinct project-level <security-list> is untouched,
since the two addresses are deliberately different in
github-advisory.md's own delivery instructions.
Fixesapache#1057
Generated-by: Claude Code (Sonnet 5)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(placeholders): the org-level security address has three names and none is registered

1 participant

@AmirF194
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(docs): collapse three org-level security placeholder names into one by AmirF194 · Pull Request #1133 · apache/magpie · GitHub
Skip to content

fix(docs): collapse three org-level security placeholder names into one - #1133

Open
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder
Open

fix(docs): collapse three org-level security placeholder names into one#1133
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder

Conversation

@AmirF194

Copy link
Copy Markdown
Contributor

Summary

  • The org-level advisory-admin security address had three names in the tree (<security-team-list>, <asf-security-list>, and the bare security_inbox.foundation_security_address config path) and none was registered in the placeholder table.
  • <asf-security-list> also bakes an ASF-specific name into a framework whose placeholder mechanism exists to keep adopting projects vendor-neutral.
  • Registers one org-neutral placeholder, <foundation-security-list>, and uses it at all three call sites. The distinct project-level <security-list> is untouched, since github-advisory.md's own delivery instructions deliberately address the two lists separately.

Type of change

  • Skill change (.claude/skills/<name>/) - eval fixtures updated below
  • Tool / bridge contract (tools/<system>/*.md)
  • Python package (tools/*/ with pyproject.toml)
  • Groovy reference impl
  • Cross-cutting (RFC, AGENTS.md, sandbox, privacy-LLM)
  • Documentation (docs/, README.md, CONTRIBUTING.md)
  • Project template (projects/_template/)
  • CI / dev loop (prek, workflows, validators)
  • Other:

Test plan

  • prek run --all-files not available in this environment (no uv/prek); ran the individual hooks by hand instead: tools/dev/check-placeholders.sh, npx markdownlint-cli2 and typos on both changed files, and the doctoc check (no TOC change needed; skills/** is excluded from the doctoc hook and AGENTS.md's TOC is unaffected by a text-only edit). All clean.
  • PYTHONPATH=tools/skill-and-tool-validator/src python3 -c "from skill_and_tool_validator import main; main()" (the same entry point uv run skill-and-tool-validate calls) reports the same 29 pre-existing soft warnings before and after this change, none on the touched files.
  • Other: did not run the Python test matrix; this PR touches no tools/*/ package.

RFC-AI-0004 compliance

  • HITL - any new mutation is gated on explicit user confirmation
  • Sandbox - no new unrestricted host access; network reach declared in the adapter
  • Vendor neutrality - replaces an ASF-branded placeholder (<asf-security-list>) with an org-neutral one, matching <governance-body> and <project-stage>
  • Conversational + correctable - agentic-override path documented if behaviour is adopter-tunable
  • Write-access discipline - no autonomous outbound messages; drafts only, sent on confirmation
  • Privacy LLM - private content does not reach a non-approved LLM; redactor invoked where needed

Linked issues

Fixes#1057

Notes for reviewers (optional)

Followed the naming this issue itself suggests, matching the config key: <foundation-security-list> rather than <org-security-list>. projects/_template/project.md already documents security_inbox.foundation_security_address as org-level and inherited ("Do not declare it here"), so no change was needed there.

The org-level advisory-admin security address had three names in the
tree: <security-team-list> in github-advisory.md, <asf-security-list>
(twice) in AGENTS.md, and the bare config path
security_inbox.foundation_security_address in the placeholder table,
which had no row for it at all. AGENTS.md also baked an ASF-specific
name into a framework whose placeholder mechanism exists precisely to
keep adopting projects out of that vocabulary.
Register <foundation-security-list>, sourced from
security_inbox.foundation_security_address, and use it at all three
call sites. The distinct project-level <security-list> is untouched,
since the two addresses are deliberately different in
github-advisory.md's own delivery instructions.
Fixesapache#1057
Generated-by: Claude Code (Sonnet 5)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(placeholders): the org-level security address has three names and none is registered

1 participant

@AmirF194
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(docs): collapse three org-level security placeholder names into one by AmirF194 · Pull Request #1133 · apache/magpie · GitHub
Skip to content

fix(docs): collapse three org-level security placeholder names into one - #1133

Open
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder
Open

fix(docs): collapse three org-level security placeholder names into one#1133
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder

Conversation

@AmirF194

Copy link
Copy Markdown
Contributor

Summary

  • The org-level advisory-admin security address had three names in the tree (<security-team-list>, <asf-security-list>, and the bare security_inbox.foundation_security_address config path) and none was registered in the placeholder table.
  • <asf-security-list> also bakes an ASF-specific name into a framework whose placeholder mechanism exists to keep adopting projects vendor-neutral.
  • Registers one org-neutral placeholder, <foundation-security-list>, and uses it at all three call sites. The distinct project-level <security-list> is untouched, since github-advisory.md's own delivery instructions deliberately address the two lists separately.

Type of change

  • Skill change (.claude/skills/<name>/) - eval fixtures updated below
  • Tool / bridge contract (tools/<system>/*.md)
  • Python package (tools/*/ with pyproject.toml)
  • Groovy reference impl
  • Cross-cutting (RFC, AGENTS.md, sandbox, privacy-LLM)
  • Documentation (docs/, README.md, CONTRIBUTING.md)
  • Project template (projects/_template/)
  • CI / dev loop (prek, workflows, validators)
  • Other:

Test plan

  • prek run --all-files not available in this environment (no uv/prek); ran the individual hooks by hand instead: tools/dev/check-placeholders.sh, npx markdownlint-cli2 and typos on both changed files, and the doctoc check (no TOC change needed; skills/** is excluded from the doctoc hook and AGENTS.md's TOC is unaffected by a text-only edit). All clean.
  • PYTHONPATH=tools/skill-and-tool-validator/src python3 -c "from skill_and_tool_validator import main; main()" (the same entry point uv run skill-and-tool-validate calls) reports the same 29 pre-existing soft warnings before and after this change, none on the touched files.
  • Other: did not run the Python test matrix; this PR touches no tools/*/ package.

RFC-AI-0004 compliance

  • HITL - any new mutation is gated on explicit user confirmation
  • Sandbox - no new unrestricted host access; network reach declared in the adapter
  • Vendor neutrality - replaces an ASF-branded placeholder (<asf-security-list>) with an org-neutral one, matching <governance-body> and <project-stage>
  • Conversational + correctable - agentic-override path documented if behaviour is adopter-tunable
  • Write-access discipline - no autonomous outbound messages; drafts only, sent on confirmation
  • Privacy LLM - private content does not reach a non-approved LLM; redactor invoked where needed

Linked issues

Fixes#1057

Notes for reviewers (optional)

Followed the naming this issue itself suggests, matching the config key: <foundation-security-list> rather than <org-security-list>. projects/_template/project.md already documents security_inbox.foundation_security_address as org-level and inherited ("Do not declare it here"), so no change was needed there.

The org-level advisory-admin security address had three names in the
tree: <security-team-list> in github-advisory.md, <asf-security-list>
(twice) in AGENTS.md, and the bare config path
security_inbox.foundation_security_address in the placeholder table,
which had no row for it at all. AGENTS.md also baked an ASF-specific
name into a framework whose placeholder mechanism exists precisely to
keep adopting projects out of that vocabulary.
Register <foundation-security-list>, sourced from
security_inbox.foundation_security_address, and use it at all three
call sites. The distinct project-level <security-list> is untouched,
since the two addresses are deliberately different in
github-advisory.md's own delivery instructions.
Fixesapache#1057
Generated-by: Claude Code (Sonnet 5)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(placeholders): the org-level security address has three names and none is registered

1 participant

@AmirF194
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(docs): collapse three org-level security placeholder names into one by AmirF194 · Pull Request #1133 · apache/magpie · GitHub
Skip to content

fix(docs): collapse three org-level security placeholder names into one - #1133

Open
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder
Open

fix(docs): collapse three org-level security placeholder names into one#1133
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder

Conversation

@AmirF194

Copy link
Copy Markdown
Contributor

Summary

  • The org-level advisory-admin security address had three names in the tree (<security-team-list>, <asf-security-list>, and the bare security_inbox.foundation_security_address config path) and none was registered in the placeholder table.
  • <asf-security-list> also bakes an ASF-specific name into a framework whose placeholder mechanism exists to keep adopting projects vendor-neutral.
  • Registers one org-neutral placeholder, <foundation-security-list>, and uses it at all three call sites. The distinct project-level <security-list> is untouched, since github-advisory.md's own delivery instructions deliberately address the two lists separately.

Type of change

  • Skill change (.claude/skills/<name>/) - eval fixtures updated below
  • Tool / bridge contract (tools/<system>/*.md)
  • Python package (tools/*/ with pyproject.toml)
  • Groovy reference impl
  • Cross-cutting (RFC, AGENTS.md, sandbox, privacy-LLM)
  • Documentation (docs/, README.md, CONTRIBUTING.md)
  • Project template (projects/_template/)
  • CI / dev loop (prek, workflows, validators)
  • Other:

Test plan

  • prek run --all-files not available in this environment (no uv/prek); ran the individual hooks by hand instead: tools/dev/check-placeholders.sh, npx markdownlint-cli2 and typos on both changed files, and the doctoc check (no TOC change needed; skills/** is excluded from the doctoc hook and AGENTS.md's TOC is unaffected by a text-only edit). All clean.
  • PYTHONPATH=tools/skill-and-tool-validator/src python3 -c "from skill_and_tool_validator import main; main()" (the same entry point uv run skill-and-tool-validate calls) reports the same 29 pre-existing soft warnings before and after this change, none on the touched files.
  • Other: did not run the Python test matrix; this PR touches no tools/*/ package.

RFC-AI-0004 compliance

  • HITL - any new mutation is gated on explicit user confirmation
  • Sandbox - no new unrestricted host access; network reach declared in the adapter
  • Vendor neutrality - replaces an ASF-branded placeholder (<asf-security-list>) with an org-neutral one, matching <governance-body> and <project-stage>
  • Conversational + correctable - agentic-override path documented if behaviour is adopter-tunable
  • Write-access discipline - no autonomous outbound messages; drafts only, sent on confirmation
  • Privacy LLM - private content does not reach a non-approved LLM; redactor invoked where needed

Linked issues

Fixes#1057

Notes for reviewers (optional)

Followed the naming this issue itself suggests, matching the config key: <foundation-security-list> rather than <org-security-list>. projects/_template/project.md already documents security_inbox.foundation_security_address as org-level and inherited ("Do not declare it here"), so no change was needed there.

The org-level advisory-admin security address had three names in the
tree: <security-team-list> in github-advisory.md, <asf-security-list>
(twice) in AGENTS.md, and the bare config path
security_inbox.foundation_security_address in the placeholder table,
which had no row for it at all. AGENTS.md also baked an ASF-specific
name into a framework whose placeholder mechanism exists precisely to
keep adopting projects out of that vocabulary.
Register <foundation-security-list>, sourced from
security_inbox.foundation_security_address, and use it at all three
call sites. The distinct project-level <security-list> is untouched,
since the two addresses are deliberately different in
github-advisory.md's own delivery instructions.
Fixesapache#1057
Generated-by: Claude Code (Sonnet 5)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(placeholders): the org-level security address has three names and none is registered

1 participant

@AmirF194
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(docs): collapse three org-level security placeholder names into one by AmirF194 · Pull Request #1133 · apache/magpie · GitHub
Skip to content

fix(docs): collapse three org-level security placeholder names into one - #1133

Open
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder
Open

fix(docs): collapse three org-level security placeholder names into one#1133
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder

Conversation

@AmirF194

Copy link
Copy Markdown
Contributor

Summary

  • The org-level advisory-admin security address had three names in the tree (<security-team-list>, <asf-security-list>, and the bare security_inbox.foundation_security_address config path) and none was registered in the placeholder table.
  • <asf-security-list> also bakes an ASF-specific name into a framework whose placeholder mechanism exists to keep adopting projects vendor-neutral.
  • Registers one org-neutral placeholder, <foundation-security-list>, and uses it at all three call sites. The distinct project-level <security-list> is untouched, since github-advisory.md's own delivery instructions deliberately address the two lists separately.

Type of change

  • Skill change (.claude/skills/<name>/) - eval fixtures updated below
  • Tool / bridge contract (tools/<system>/*.md)
  • Python package (tools/*/ with pyproject.toml)
  • Groovy reference impl
  • Cross-cutting (RFC, AGENTS.md, sandbox, privacy-LLM)
  • Documentation (docs/, README.md, CONTRIBUTING.md)
  • Project template (projects/_template/)
  • CI / dev loop (prek, workflows, validators)
  • Other:

Test plan

  • prek run --all-files not available in this environment (no uv/prek); ran the individual hooks by hand instead: tools/dev/check-placeholders.sh, npx markdownlint-cli2 and typos on both changed files, and the doctoc check (no TOC change needed; skills/** is excluded from the doctoc hook and AGENTS.md's TOC is unaffected by a text-only edit). All clean.
  • PYTHONPATH=tools/skill-and-tool-validator/src python3 -c "from skill_and_tool_validator import main; main()" (the same entry point uv run skill-and-tool-validate calls) reports the same 29 pre-existing soft warnings before and after this change, none on the touched files.
  • Other: did not run the Python test matrix; this PR touches no tools/*/ package.

RFC-AI-0004 compliance

  • HITL - any new mutation is gated on explicit user confirmation
  • Sandbox - no new unrestricted host access; network reach declared in the adapter
  • Vendor neutrality - replaces an ASF-branded placeholder (<asf-security-list>) with an org-neutral one, matching <governance-body> and <project-stage>
  • Conversational + correctable - agentic-override path documented if behaviour is adopter-tunable
  • Write-access discipline - no autonomous outbound messages; drafts only, sent on confirmation
  • Privacy LLM - private content does not reach a non-approved LLM; redactor invoked where needed

Linked issues

Fixes#1057

Notes for reviewers (optional)

Followed the naming this issue itself suggests, matching the config key: <foundation-security-list> rather than <org-security-list>. projects/_template/project.md already documents security_inbox.foundation_security_address as org-level and inherited ("Do not declare it here"), so no change was needed there.

The org-level advisory-admin security address had three names in the
tree: <security-team-list> in github-advisory.md, <asf-security-list>
(twice) in AGENTS.md, and the bare config path
security_inbox.foundation_security_address in the placeholder table,
which had no row for it at all. AGENTS.md also baked an ASF-specific
name into a framework whose placeholder mechanism exists precisely to
keep adopting projects out of that vocabulary.
Register <foundation-security-list>, sourced from
security_inbox.foundation_security_address, and use it at all three
call sites. The distinct project-level <security-list> is untouched,
since the two addresses are deliberately different in
github-advisory.md's own delivery instructions.
Fixesapache#1057
Generated-by: Claude Code (Sonnet 5)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(placeholders): the org-level security address has three names and none is registered

1 participant

@AmirF194
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(docs): collapse three org-level security placeholder names into one by AmirF194 · Pull Request #1133 · apache/magpie · GitHub
Skip to content

fix(docs): collapse three org-level security placeholder names into one - #1133

Open
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder
Open

fix(docs): collapse three org-level security placeholder names into one#1133
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder

Conversation

@AmirF194

Copy link
Copy Markdown
Contributor

Summary

  • The org-level advisory-admin security address had three names in the tree (<security-team-list>, <asf-security-list>, and the bare security_inbox.foundation_security_address config path) and none was registered in the placeholder table.
  • <asf-security-list> also bakes an ASF-specific name into a framework whose placeholder mechanism exists to keep adopting projects vendor-neutral.
  • Registers one org-neutral placeholder, <foundation-security-list>, and uses it at all three call sites. The distinct project-level <security-list> is untouched, since github-advisory.md's own delivery instructions deliberately address the two lists separately.

Type of change

  • Skill change (.claude/skills/<name>/) - eval fixtures updated below
  • Tool / bridge contract (tools/<system>/*.md)
  • Python package (tools/*/ with pyproject.toml)
  • Groovy reference impl
  • Cross-cutting (RFC, AGENTS.md, sandbox, privacy-LLM)
  • Documentation (docs/, README.md, CONTRIBUTING.md)
  • Project template (projects/_template/)
  • CI / dev loop (prek, workflows, validators)
  • Other:

Test plan

  • prek run --all-files not available in this environment (no uv/prek); ran the individual hooks by hand instead: tools/dev/check-placeholders.sh, npx markdownlint-cli2 and typos on both changed files, and the doctoc check (no TOC change needed; skills/** is excluded from the doctoc hook and AGENTS.md's TOC is unaffected by a text-only edit). All clean.
  • PYTHONPATH=tools/skill-and-tool-validator/src python3 -c "from skill_and_tool_validator import main; main()" (the same entry point uv run skill-and-tool-validate calls) reports the same 29 pre-existing soft warnings before and after this change, none on the touched files.
  • Other: did not run the Python test matrix; this PR touches no tools/*/ package.

RFC-AI-0004 compliance

  • HITL - any new mutation is gated on explicit user confirmation
  • Sandbox - no new unrestricted host access; network reach declared in the adapter
  • Vendor neutrality - replaces an ASF-branded placeholder (<asf-security-list>) with an org-neutral one, matching <governance-body> and <project-stage>
  • Conversational + correctable - agentic-override path documented if behaviour is adopter-tunable
  • Write-access discipline - no autonomous outbound messages; drafts only, sent on confirmation
  • Privacy LLM - private content does not reach a non-approved LLM; redactor invoked where needed

Linked issues

Fixes#1057

Notes for reviewers (optional)

Followed the naming this issue itself suggests, matching the config key: <foundation-security-list> rather than <org-security-list>. projects/_template/project.md already documents security_inbox.foundation_security_address as org-level and inherited ("Do not declare it here"), so no change was needed there.

The org-level advisory-admin security address had three names in the
tree: <security-team-list> in github-advisory.md, <asf-security-list>
(twice) in AGENTS.md, and the bare config path
security_inbox.foundation_security_address in the placeholder table,
which had no row for it at all. AGENTS.md also baked an ASF-specific
name into a framework whose placeholder mechanism exists precisely to
keep adopting projects out of that vocabulary.
Register <foundation-security-list>, sourced from
security_inbox.foundation_security_address, and use it at all three
call sites. The distinct project-level <security-list> is untouched,
since the two addresses are deliberately different in
github-advisory.md's own delivery instructions.
Fixesapache#1057
Generated-by: Claude Code (Sonnet 5)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(placeholders): the org-level security address has three names and none is registered

1 participant

@AmirF194
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(docs): collapse three org-level security placeholder names into one by AmirF194 · Pull Request #1133 · apache/magpie · GitHub
Skip to content

fix(docs): collapse three org-level security placeholder names into one - #1133

Open
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder
Open

fix(docs): collapse three org-level security placeholder names into one#1133
AmirF194 wants to merge 1 commit into
apache:mainfrom
AmirF194:fix/1057-foundation-security-list-placeholder

Conversation

@AmirF194

Copy link
Copy Markdown
Contributor

Summary

  • The org-level advisory-admin security address had three names in the tree (<security-team-list>, <asf-security-list>, and the bare security_inbox.foundation_security_address config path) and none was registered in the placeholder table.
  • <asf-security-list> also bakes an ASF-specific name into a framework whose placeholder mechanism exists to keep adopting projects vendor-neutral.
  • Registers one org-neutral placeholder, <foundation-security-list>, and uses it at all three call sites. The distinct project-level <security-list> is untouched, since github-advisory.md's own delivery instructions deliberately address the two lists separately.

Type of change

  • Skill change (.claude/skills/<name>/) - eval fixtures updated below
  • Tool / bridge contract (tools/<system>/*.md)
  • Python package (tools/*/ with pyproject.toml)
  • Groovy reference impl
  • Cross-cutting (RFC, AGENTS.md, sandbox, privacy-LLM)
  • Documentation (docs/, README.md, CONTRIBUTING.md)
  • Project template (projects/_template/)
  • CI / dev loop (prek, workflows, validators)
  • Other:

Test plan

  • prek run --all-files not available in this environment (no uv/prek); ran the individual hooks by hand instead: tools/dev/check-placeholders.sh, npx markdownlint-cli2 and typos on both changed files, and the doctoc check (no TOC change needed; skills/** is excluded from the doctoc hook and AGENTS.md's TOC is unaffected by a text-only edit). All clean.
  • PYTHONPATH=tools/skill-and-tool-validator/src python3 -c "from skill_and_tool_validator import main; main()" (the same entry point uv run skill-and-tool-validate calls) reports the same 29 pre-existing soft warnings before and after this change, none on the touched files.
  • Other: did not run the Python test matrix; this PR touches no tools/*/ package.

RFC-AI-0004 compliance

  • HITL - any new mutation is gated on explicit user confirmation
  • Sandbox - no new unrestricted host access; network reach declared in the adapter
  • Vendor neutrality - replaces an ASF-branded placeholder (<asf-security-list>) with an org-neutral one, matching <governance-body> and <project-stage>
  • Conversational + correctable - agentic-override path documented if behaviour is adopter-tunable
  • Write-access discipline - no autonomous outbound messages; drafts only, sent on confirmation
  • Privacy LLM - private content does not reach a non-approved LLM; redactor invoked where needed

Linked issues

Fixes#1057

Notes for reviewers (optional)

Followed the naming this issue itself suggests, matching the config key: <foundation-security-list> rather than <org-security-list>. projects/_template/project.md already documents security_inbox.foundation_security_address as org-level and inherited ("Do not declare it here"), so no change was needed there.

The org-level advisory-admin security address had three names in the
tree: <security-team-list> in github-advisory.md, <asf-security-list>
(twice) in AGENTS.md, and the bare config path
security_inbox.foundation_security_address in the placeholder table,
which had no row for it at all. AGENTS.md also baked an ASF-specific
name into a framework whose placeholder mechanism exists precisely to
keep adopting projects out of that vocabulary.
Register <foundation-security-list>, sourced from
security_inbox.foundation_security_address, and use it at all three
call sites. The distinct project-level <security-list> is untouched,
since the two addresses are deliberately different in
github-advisory.md's own delivery instructions.
Fixesapache#1057
Generated-by: Claude Code (Sonnet 5)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(placeholders): the org-level security address has three names and none is registered

1 participant

@AmirF194