Skip to content

chore: add security policy - #707

Merged
alexey-igrychev merged 1 commit into
mainfrom
chore/add-security-policy
Sep 1, 2026
Merged

chore: add security policy#707
alexey-igrychev merged 1 commit into
mainfrom
chore/add-security-policy

Conversation

@alexey-igrychev

@alexey-igrychev alexey-igrychev commented Sep 1, 2026

Copy link
Copy Markdown
Member

Summary

nelm now publishes project-level guidance for responsibly reporting security vulnerabilities and explains how accepted vulnerabilities are publicly disclosed.

What

  • Security reports are directed to cncf-werf-security@lists.cncf.io.
  • Vulnerability details are treated confidentially.
  • Public disclosure happens through release notes and credits reporters unless they prefer anonymity.

Why

The repository previously had no security policy, leaving reporters without a documented disclosure channel or expectations for handling and publication.

Review in cubic

Document the responsible disclosure channel and public disclosure process. Previously, the repository did not provide project-level vulnerability reporting guidance.

Signed-off-by: Aleksei Igrychev <aleksei.igrychev@palark.com>
@alexey-igrychev
alexey-igrychev marked this pull request as ready for review September 1, 2026 15:03
@alexey-igrychev
alexey-igrychev merged commit 454f89b into main Sep 1, 2026
4 checks passed
@alexey-igrychev
alexey-igrychev deleted the chore/add-security-policy branch September 1, 2026 15:03
@alexey-igrychev
alexey-igrychev restored the chore/add-security-policy branch September 1, 2026 15:03
@alexey-igrychev
alexey-igrychev deleted the chore/add-security-policy branch September 1, 2026 15:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant