Public release release-6d1a121b0a8a
Source commit: 6d1a121b0a8a636aac95998fe5d15c24c78eb7d0 Public tree identity: sha256:2bc22807f5b838286678b65d3f550b8ae4714ae673622041d4c2516a7c5b7926
This commit is contained in:
commit
21f097d9a8
210 changed files with 78649 additions and 0 deletions
18
SECURITY.md
Normal file
18
SECURITY.md
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
# Security reporting
|
||||
|
||||
## Supported versions
|
||||
|
||||
Security fixes are applied to the current main branch and the most recent
|
||||
published Clusterflux release. Older preview releases are not maintained.
|
||||
|
||||
## Report a vulnerability
|
||||
|
||||
Email security@michelpaulissen.com with a concise description, affected version
|
||||
or source revision, reproduction steps, and impact. Do not open a public issue
|
||||
for an unpatched vulnerability or include credentials, session tokens, private
|
||||
keys, provider tokens, customer data, or operator secrets in a public report.
|
||||
|
||||
You should receive an acknowledgement within three business days. We will
|
||||
coordinate validation, remediation, release timing, and disclosure with you.
|
||||
Avoid accessing data that is not yours, disrupting the hosted service, or
|
||||
retaining sensitive data beyond what is necessary to demonstrate the issue.
|
||||
Loading…
Add table
Add a link
Reference in a new issue