Skip to content

Commit 94cdfe8

Browse files
ai-ram-ramaniramaniraharmjeff
authored
Add disclaimer for security baseline extension (#127)
Co-authored-by: ai-ram-ramani <ramanira@amazon.com> Co-authored-by: Jeff Harman <109810187+harmjeff@users.noreply.github.com>
1 parent aaca23d commit 94cdfe8

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

README.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -528,6 +528,9 @@ Here's the general flow once an extension is enabled:
528528

529529
The workflow currently ships with a baseline security extension.
530530

531+
> [!IMPORTANT]
532+
> The security extension rules are based on the [OWASP Top 10](https://owasp.org/www-project-top-ten/) and have been tested through controlled experimentation (see [PR #80](https://github.com/awslabs/aidlc-workflows/pull/80)). They are provided as a directional reference for building effective security rules within AI-DLC workflows. Each organization should build, customize, and thoroughly test their own security rules before deploying in production workflows.
533+
531534
```
532535
aws-aidlc-rule-details/
533536
└── extensions/

0 commit comments

Comments
 (0)