Skip to content

Security: cncf/project-template

SECURITY.md

Security Policy

Instructions

Reporting a Vulnerability

If you discover a security vulnerability in [TODO: PROJECTNAME], please report it responsibly. Do not open a public GitHub issue.

To report a vulnerability, use one of the following methods:

Please include in your report:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Affected versions
  • Any potential impact you have identified

Response Timeline

The [TODO: PROJECTNAME] security team will acknowledge receipt of your report within [TODO: Number, e.g. 3] business days and will provide an estimated timeline for a fix within [TODO: Number, e.g. 10] business days.

The team will keep you informed of progress toward a fix and may ask for additional information.

Supported Versions

Version Supported
x.y.z Yes
< x.y No

Disclosure Policy

When a security issue is confirmed, the [TODO: PROJECTNAME] team will:

  1. Develop and test a fix
  2. Assign a CVE identifier if appropriate
  3. Release a patched version
  4. Publish a security advisory via [GitHub Security Advisories](TODO: Link to https://github.com/ORG/REPO/security/advisories)

Security Response Team

The security response team handles all reports of security vulnerabilities according to this policy. See GOVERNANCE.md for how the security response team is appointed and maintained.

Current security response team members are listed in MAINTAINERS.md or designated by the maintainer council.

Security Best Practices

Projects applying to move levels within the CNCF are expected to demonstrate:

There aren't any published security advisories