Skip to content

Validate process to report security issues #37

Description

@nimbinatus

Clearly defined and discoverable process to report security issues.

Should be a link to a section in the security docs, iirc.

Activity

  1. added theissue type on Jul 2, 2026
  2. mohan-shash commented on Jul 10, 2026

    @mohan-shash
    Collaborator

    bootc meets both CNCF security documentation requirements:

    1. Clearly defined and discoverable process to report security issues:

    2. Document assignment of security response roles and how reports are handled:

    Comparison with CNCF Graduated Projects:

    • Uses same reporting method as containerd (GitHub Security Advisories)
    • Better cross-referencing than Kubernetes (external docs) or containerd (separate repo)
    • Appropriate depth for incubation stage

    Both requirements fully met. ✅

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions