Skip to content

Files

Latest commit

 

History

History
24 lines (14 loc) Β· 1.22 KB

SECURITY.md

File metadata and controls

24 lines (14 loc) Β· 1.22 KB

Security Policy

This document outlines the security policies, including how to report vulnerabilities, verify artifact integrity, and understand the security measures in place.

πŸ“’ Reporting a Vulnerability

We take security seriously. If you discover a vulnerability in ggbridge, please report it using our confidentially our Vulnerability Disclosure Portal.

Please avoid reporting security issues in public GitHub issues or discussions.


πŸ”‘ Provenance and Supply Chain Security

To ensure the integrity of our software, we provide a verifiable provenance for our Docker images. You can find all provenance attestations here.

πŸ—οΈ Build Provenance

Our wolfi-based container images are built using GitHub Actions and follow best practices for supply chain security with a declarative approach leveraging apko.