Skip to content

docs: strengthen vulnerability reporting policy - #94

Merged
yada merged 1 commit into
mainfrom
security/harden-vulnerability-reporting
Sep 8, 2026
Merged

docs: strengthen vulnerability reporting policy#94
yada merged 1 commit into
mainfrom
security/harden-vulnerability-reporting

Conversation

@yada

@yada yada commented Sep 8, 2026

Copy link
Copy Markdown
Member

Description

  • Require suspected vulnerabilities to be reported privately to security@microcks.io.
  • Define the information reporters should include and establish a five-business-day acknowledgement target.
  • Establish a coordinated disclosure target of 90 calendar days, with documented conditions for extensions.
  • Clarify supported-version handling, advisory publication and Security Team responsibilities.
  • Remove public GitHub Discussions as a vulnerability-reporting channel.

This update addresses the security-policy recommendations raised during the CNCF project review.

Once merged, SECURITY.md will be replicated to the Microcks repositories where it is needed and relevant.

Related issue(s)

See also cncf/toc#2099

Signed-off-by: Yacine Kheddache <yacine@microcks.io>
@yada yada self-assigned this Sep 8, 2026
@yada yada added the documentation Improvements or additions to documentation label Sep 8, 2026
@yada
yada merged commit 646c17d into main Sep 8, 2026
4 checks passed
@yada

yada commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

My vote: +1 (binding)

1 similar comment
@SebastienDegodez

Copy link
Copy Markdown
Member

My vote: +1 (binding)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants