diff --git a/AGENTS.md b/AGENTS.md index 17438c5f..3149dd74 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -383,6 +383,7 @@ configuration before executing any command: | `` | GitHub slug of the (security) tracker repo (example: `airflow-s/airflow-s`). | `/project.md` → `tracker_repo` | | `` | GitHub slug of the upstream codebase the fixes land in (example: `apache/airflow`). | `/project.md` → `upstream_repo` | | `` | The project's security mailing list (example: `security@airflow.apache.org`). | `/project.md` → `security_list` (under **Mailing lists**) | +| `` | The org-level advisory-admin security address, distinct from the project's own `` (example: `security@apache.org`). Inherited, not declared per-project. | organization manifest → `security_inbox.foundation_security_address` | | `` | URL of the project's general-issue tracker, distinct from the security tracker. | `/issue-tracker-config.md` → `url` | | `` | Project key within the issue tracker (JIRA key or `owner/repo`). | `/issue-tracker-config.md` → `project_key` | | `` | Recipe for invoking the project's runtime on a single source file. | `/runtime-invocation.md` | @@ -663,7 +664,7 @@ While triaging a report, you may learn about vulnerabilities in **other ASF projects** through the same channels that surface our own reports: the reporter's mail thread mentions that they filed a similar issue against Superset or Allura; a cross-project digest on -`` summarises active reports across several +`` summarises active reports across several projects; a Gmail search for a CVE ID or a vulnerability pattern returns hits on threads belonging to unrelated projects; your own deduction from a reporter's résumé or prior disclosures correlates @@ -722,7 +723,7 @@ channel they arrived on: against Superset and Allura"* is not. *"A sibling ASF project landed a comparable fix"* is allowed; *"Tomcat landed the equivalent fix in 11.0.3"* is not. -- Cross-project triage belongs on `` or in a +- Cross-project triage belongs on `` or in a direct mail to that project's security team, not in our tracker. **Self-check before posting, committing, or drafting.** Grep the diff --git a/skills/security-issue-sync/github-advisory.md b/skills/security-issue-sync/github-advisory.md index c5d50280..bb1d2146 100644 --- a/skills/security-issue-sync/github-advisory.md +++ b/skills/security-issue-sync/github-advisory.md @@ -126,7 +126,7 @@ path. ### Delivery — an email relay (draft, never auto-sent) Create a **draft** email to the org's advisory-admin security team -(``) with +(``) with `oauth-draft-create` — never send directly (SKILL Golden rule 1; and the Gmail MCP mangles the `security/advisories/GHSA-…` URLs into redirects, so use oauth-draft). **Always CC the project ``** so the