SECURITY.md: Use GitHub Security Advisory for reports#462
SECURITY.md: Use GitHub Security Advisory for reports#462rhatdan merged 1 commit intocontainers:mainfrom
Conversation
Reviewer's GuideReplaces the old reference-based security policy with a self-contained SECURITY.md that directs reporters to use GitHub Security Advisories for private vulnerability disclosure, including concrete reporting steps and expectations. File-Level Changes
Assessment against linked issues
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
@containers/container-selinux-maintainers PTAL |
There was a problem hiding this comment.
Code Review
This pull request updates the SECURITY.md file to include a comprehensive policy for reporting security vulnerabilities, replacing the previous external link. The new content details the reporting process via GitHub Security Advisories and outlines the expected response from maintainers. Feedback focuses on improving the clarity of the instructions by removing redundant warnings and ensuring consistent punctuation across the document.
|
NOTE: People without github accounts would find it hard to report issues, but then again, we don't receive frequent reports for container-selinux anyway, so I assume that possiblity to be minuscule. |
953c027 to
9c778bd
Compare
|
Ephemeral COPR build failed. @containers/packit-build please check. |
Podman and other CNCF projects will soon be moving to another GitHub org so we can't continue to depend on SECURITY.md in container-libs. Copied from containers/ramalama with modifications. Fixes: containers#461 Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> Signed-off-by: Lokesh Mandvekar <[email protected]>
a7fc40f to
5b2d20d
Compare
|
LGTM |
Podman and other CNCF projects will soon be moving to another GitHub org so we can't continue to depend on SECURITY.md in container-libs.
Copied from containers/ramalama with modifications.
Fixes: #461
Summary by Sourcery
Documentation: