docs: point CLAUDE.md at THREAT_MODEL.md for security scope - #1885
Merged
Conversation
The "Security Reports & Scans" section named SECURITY.md and AGENTS.md but not THREAT_MODEL.md, so anything working from CLAUDE.md alone reached the reporting process without the scope that decides whether there is anything to report. THREAT_MODEL.md was only reachable transitively, via a link in SECURITY.md or AGENTS.md. Name it directly, and say what it is for: the recurring non-findings (§11a) and the triage dispositions (§13) are what separate a real finding from a documented non-issue. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AtyHU8BzNmeZNncXRu7yjB
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



The Security Reports & Scans section of
CLAUDE.mdnamedSECURITY.mdandAGENTS.mdbut notTHREAT_MODEL.md. Anything working fromCLAUDE.mdalone therefore reached the reporting process without the scope that decides whether there is anything to report —THREAT_MODEL.mdwas only reachable transitively, through a link inSECURITY.md:8orAGENTS.md:17.This matters most for automated review. A generic security pass over a Struts diff will confidently flag unannotated setters, direct JSP access, raw
${}EL and "generic DoS" — every one of whichTHREAT_MODEL.md§11a already closes as a known non-finding, and §13 routes toOUT-OF-MODEL: application-responsibilityornon-default-config.So name the file directly and say what it is for.
Documentation only — no ticket, per the
docs:convention inCLAUDE.md. No code, build or CI files touched.🤖 Generated with Claude Code
https://claude.ai/code/session_01AtyHU8BzNmeZNncXRu7yjB