Security Policy
August 3, 2026 ยท View on GitHub
Reporting a Vulnerability
If you discover a security vulnerability in [TODO: PROJECTNAME], please report it responsibly. Do not open a public GitHub issue.
To report a vulnerability, use one of the following methods:
- GitHub Private Vulnerability Reporting: [Report a vulnerability](TODO: Link to https://github.com/ORG/REPO/security/advisories/new)
- Email: Send a report to [TODO: security email, e.g. security@projectname.dev]
Please include in your report:
- Description of the vulnerability
- Steps to reproduce the issue
- Affected versions
- Any potential impact you have identified
Response Timeline
The [TODO: PROJECTNAME] security team will acknowledge receipt of your report within [TODO: Number, e.g. 3] business days and will provide an estimated timeline for a fix within [TODO: Number, e.g. 10] business days.
The team will keep you informed of progress toward a fix and may ask for additional information.
Supported Versions
| Version | Supported |
|---|---|
| x.y.z | Yes |
| < x.y | No |
Disclosure Policy
When a security issue is confirmed, the [TODO: PROJECTNAME] team will:
- Develop and test a fix
- Assign a CVE identifier if appropriate
- Release a patched version
- Publish a security advisory via [GitHub Security Advisories](TODO: Link to https://github.com/ORG/REPO/security/advisories)
Security Response Team
The security response team handles all reports of security vulnerabilities according to this policy. See GOVERNANCE.md for how the security response team is appointed and maintained.
Current security response team members are listed in MAINTAINERS.md or designated by the maintainer council.
Security Best Practices
Projects applying to move levels within the CNCF are expected to demonstrate:
- OpenSSF Best Practices Badge - [TODO: Add your badge link, e.g.
]
- Security Self-Assessment completed and submitted to the CNCF TOC
- Dependency management via automated tools (e.g. Dependabot, Renovate)
- Signed releases and/or Software Bill of Materials (SBOM)