Skip to content

Commit a045c49

Browse files
[Feature] Security Improvements based on CLOMonitor Checks (kyverno#9395)
* Added Security Insights Signed-off-by: coder12git <[email protected]> * add self-assesssment evidence url Signed-off-by: coder12git <[email protected]> * updated changes Signed-off-by: coder12git <[email protected]> * set bug-bounty to false Signed-off-by: coder12git <[email protected]> --------- Signed-off-by: coder12git <[email protected]> Co-authored-by: Jim Bugwadia <[email protected]>
1 parent 5905ab9 commit a045c49

File tree

1 file changed

+62
-0
lines changed

1 file changed

+62
-0
lines changed

SECURITY-INSIGHTS.yml

+62
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,62 @@
1+
header:
2+
schema-version: 1.0.0
3+
expiration-date: '2025-01-15T01:00:00.000Z'
4+
project-url: 'https://github.com/kyverno/kyverno'
5+
license: 'https://github.com/kyverno/kyverno/blob/main/LICENSE'
6+
project-lifecycle:
7+
bug-fixes-only: false
8+
core-maintainers:
9+
- https://github.com/kyverno/kyverno/blob/main/MAINTAINERS.md
10+
status: active
11+
release-process: 'https://github.com/kyverno/kyverno/releases'
12+
contribution-policy:
13+
accepts-pull-requests: true
14+
accepts-automated-pull-requests: true
15+
automated-tools-list:
16+
- automated-tool: dependabot
17+
action: allowed
18+
path:
19+
- /
20+
contributing-policy: 'https://github.com/kyverno/kyverno/blob/main/CONTRIBUTING.md'
21+
code-of-conduct:
22+
- 'https://github.com/kyverno/kyverno/blob/main/CODE_OF_CONDUCT.md'
23+
documentation:
24+
- 'https://kyverno.io/docs/'
25+
distribution-points:
26+
- 'https://github.com/orgs/kyverno/packages'
27+
security-artifacts:
28+
threat-model:
29+
threat-model-created: true
30+
evidence-url:
31+
- 'https://kyverno.io/docs/security/#threat-model'
32+
self-assessment:
33+
self-assessment-created: true
34+
evidence-url:
35+
- https://github.com/cncf/tag-security/blob/main/assessments/projects/kyverno/self-assessment.md
36+
security-testing:
37+
- tool-type: sca
38+
tool-name: Dependabot
39+
tool-version: "2"
40+
tool-url: https://github.com/dependabot
41+
integration:
42+
ad-hoc: false
43+
ci: true
44+
before-release: true
45+
security-contacts:
46+
- type: email
47+
48+
primary: true
49+
vulnerability-reporting:
50+
accepts-vulnerability-reports: true
51+
email-contact: [email protected]
52+
security-policy: 'https://kyverno.io/docs/security/'
53+
bug-bounty-available: false
54+
bug-bounty-url: ''
55+
dependencies:
56+
third-party-packages: true
57+
dependencies-lists:
58+
- 'https://github.com/kyverno/kyverno/blob/main/go.mod'
59+
dependencies-lifecycle:
60+
policy-url: 'https://kyverno.io/docs/installation/#compatibility-matrix'
61+
env-dependencies-policy:
62+
policy-url: ''

0 commit comments

Comments
 (0)