Skip to content

docs: point CLAUDE.md at THREAT_MODEL.md for security scope - #1885

Merged
lukaszlenart merged 1 commit into
mainfrom
docs/claude-md-threat-model
Aug 30, 2026
Merged

docs: point CLAUDE.md at THREAT_MODEL.md for security scope#1885
lukaszlenart merged 1 commit into
mainfrom
docs/claude-md-threat-model

Conversation

@lukaszlenart

Copy link
Copy Markdown
Member

The Security Reports & Scans section of CLAUDE.md named SECURITY.md and AGENTS.md but not THREAT_MODEL.md. Anything working from CLAUDE.md alone therefore reached the reporting process without the scope that decides whether there is anything to report — THREAT_MODEL.md was only reachable transitively, through a link in SECURITY.md:8 or AGENTS.md:17.

This matters most for automated review. A generic security pass over a Struts diff will confidently flag unannotated setters, direct JSP access, raw ${} EL and "generic DoS" — every one of which THREAT_MODEL.md §11a already closes as a known non-finding, and §13 routes to OUT-OF-MODEL: application-responsibility or non-default-config.

So name the file directly and say what it is for.

Documentation only — no ticket, per the docs: convention in CLAUDE.md. No code, build or CI files touched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01AtyHU8BzNmeZNncXRu7yjB

The "Security Reports & Scans" section named SECURITY.md and AGENTS.md but
not THREAT_MODEL.md, so anything working from CLAUDE.md alone reached the
reporting process without the scope that decides whether there is anything
to report. THREAT_MODEL.md was only reachable transitively, via a link in
SECURITY.md or AGENTS.md.

Name it directly, and say what it is for: the recurring non-findings (§11a)
and the triage dispositions (§13) are what separate a real finding from a
documented non-issue.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AtyHU8BzNmeZNncXRu7yjB
@sonarqubecloud

Copy link
Copy Markdown

@lukaszlenart
lukaszlenart marked this pull request as ready for review August 30, 2026 15:20
@lukaszlenart
lukaszlenart merged commit 16415ad into main Aug 30, 2026
11 of 12 checks passed
@lukaszlenart
lukaszlenart deleted the docs/claude-md-threat-model branch August 30, 2026 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant