-
Notifications
You must be signed in to change notification settings - Fork 75
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add SECURITY.md security policy #35
Conversation
@tallclair: The label(s) In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
/committee product-security |
/lgtm |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you!
/approve
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: joelsmith, nikhita, tallclair The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Bump -- GitHub's search API hasn't been consistent these days, which means prow doesn't pick up PRs with |
@nuthinking @neovintage this is what i mentioned when we were talking last week. we see the glitches from GitHub's search API pretty regularly and our bots have trouble due to the changes in behavior :( |
Is there any tooling to help update all our repos with the new file, or do I need to script it up myself? |
I have a |
Thanks Joel. If you have bandwidth to handle it, that would be great. Alternatively, we might want to wait and see where the |
Yep, I can handle it. Better that only one of has to fork every single k8s repo ;-) |
All PRs are now open and they all link back to the master issue: kubernetes/committee-security-response#105 Do we need to do the same thing for any other GitHub orgs, such as kubernetes-sigs? |
Thanks! I think we should probably add it for kubernetes-sigs too, even if a lot of those projects aren't eligible for bug-bounty. |
There are a lot of kubernetes-sigs repos. I wonder if instead of opening a PR against each with the added file, what if we create a kubernetes-sig/.github repo? Apparently, if you create a repo named According to the docs:
The linked doc says:
|
👍 💯 |
Now that github has official support for security policies, some users may expect to find disclosure protocols there. We should make sure every one of our repos links the security policy to https://kubernetes.io/docs/reference/issues-security/security/#report-a-vulnerability to avoid accidental disclosures.
I was originally thinking of merging
SECRUITY_CONTACTS
intoSECURITY.md
, but the future of SECURITY_CONTACTS is under active discussion. I'm also worried that people looking for who to contact might reach out to security contacts rather than following our disclosure process (part of the larger discussion).