SECURITY-INSIGHTS.yml 1.5 KB

1234567891011121314151617181920212223242526272829303132333435363738
  1. header:
  2. schema-version: '1.0.0'
  3. expiration-date: '2024-11-04T10:00:00.000Z'
  4. project-url: https://github.com/argoproj/argo-helm
  5. project-lifecycle:
  6. status: active
  7. bug-fixes-only: false
  8. core-maintainers:
  9. - https://github.com/mkilchhofer
  10. - https://github.com/jmeridth
  11. contribution-policy:
  12. accepts-pull-requests: true
  13. accepts-automated-pull-requests: true
  14. automated-tools-list:
  15. - automated-tool: dependabot
  16. action: allowed
  17. path:
  18. - /
  19. contributing-policy: https://github.com/argoproj/argo-helm/blob/main/CONTRIBUTING.md
  20. code-of-conduct: https://github.com/cncf/foundation/blob/master/code-of-conduct.md
  21. distribution-points:
  22. - https://argoproj.github.io/argo-helm
  23. - https://artifacthub.io/packages/search?org=argoproj&repo=argo
  24. security-contacts:
  25. - type: website
  26. value: https://github.com/argoproj/argo-helm/security/advisories/new
  27. primary: true
  28. vulnerability-reporting:
  29. accepts-vulnerability-reports: true
  30. email-contact: cncf-argo-maintainers@lists.cncf.io
  31. security-policy: https://github.com/argoproj/argo-helm/blob/main/SECURITY.md
  32. comment: |
  33. Our preferred contact method related to vulnerabilities is the Security tab on GitHub.
  34. Click the button "Report a vulnerability" to open the advisory form.
  35. Please refer to the security policy for reporting information prior to using the email contact.
  36. dependencies:
  37. env-dependencies-policy:
  38. policy-url: https://github.com/argoproj/argo-helm/blob/master/CONTRIBUTING.md#new-application-versions