Apache Shiro's security model and disclosure process are published on the project website rather than in the repository:
- Threat and security model: https://shiro.apache.org/security-model.html
- Security policy, vulnerability reporting, past advisories and CVEs: https://shiro.apache.org/security-reports.html
The project website is the authoritative source; this file
exists so agents and tooling that look for SECURITY.md in
the repository can mechanically follow the link to the
canonical documents.