Skip to content

Security: BerryBytes/01cloud-tekton-ci

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are provided for the latest stable release line.

Version Supported
latest

Reporting a Vulnerability

Please do not disclose security issues publicly in GitHub issues, discussions, or pull requests.

Report vulnerabilities privately by email:

What to Include in a Report

Please include as much of the following as possible:

  • Vulnerability type and impacted component(s)
  • Steps to reproduce or proof of concept
  • Potential impact and attack prerequisites
  • Suggested remediation (optional)
  • Your preferred contact details

Disclosure Process

  1. We acknowledge receipt of valid reports within 3 business days.
  2. We investigate and validate the issue.
  3. We work on remediation and coordinate release timing.
  4. We notify the reporter when a fix is available.

We follow responsible disclosure and request that reporters avoid public disclosure until a fix is released.

Safe Harbor

If you act in good faith, avoid privacy violations and service disruption, and do not exfiltrate data, we will not pursue legal action for your research.

There aren't any published security advisories