If you discover a security vulnerability in [TODO: PROJECTNAME], please report it responsibly. Do not open a public GitHub issue.
To report a vulnerability, use one of the following methods:
- GitHub Private Vulnerability Reporting: [Report a vulnerability](TODO: Link to https://github.com/ORG/REPO/security/advisories/new)
- Email: Send a report to [TODO: security email, e.g. security@projectname.dev]
Please include in your report:
- Description of the vulnerability
- Steps to reproduce the issue
- Affected versions
- Any potential impact you have identified
The [TODO: PROJECTNAME] security team will acknowledge receipt of your report within [TODO: Number, e.g. 3] business days and will provide an estimated timeline for a fix within [TODO: Number, e.g. 10] business days.
The team will keep you informed of progress toward a fix and may ask for additional information.
| Version | Supported |
|---|---|
| x.y.z | Yes |
| < x.y | No |
When a security issue is confirmed, the [TODO: PROJECTNAME] team will:
- Develop and test a fix
- Assign a CVE identifier if appropriate
- Release a patched version
- Publish a security advisory via [GitHub Security Advisories](TODO: Link to https://github.com/ORG/REPO/security/advisories)
The security response team handles all reports of security vulnerabilities according to this policy. See GOVERNANCE.md for how the security response team is appointed and maintained.
Current security response team members are listed in MAINTAINERS.md or designated by the maintainer council.
Projects applying to move levels within the CNCF are expected to demonstrate:
- OpenSSF Best Practices Badge - [TODO: Add your badge link, e.g.
]
- Security Self-Assessment completed and submitted to the CNCF TOC
- Dependency management via automated tools (e.g. Dependabot, Renovate)
- Signed releases and/or Software Bill of Materials (SBOM)