1 Star 0 Fork 33

赵恺彬 / kubesphere

forked from KubeSphere / kubesphere 
加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
克隆/下载
SECURITY.md 2.03 KB
一键复制 编辑 原始数据 按行查看 历史
Calvin Yu 提交于 2022-06-15 10:12 . Create SECURITY.md

Security Policy

Supported Versions

Use this section to tell people about which versions of your project are currently being supported with security updates.

Version Supported
3.2.x :white_check_mark:
3.1.x :white_check_mark:
3.0.x :white_check_mark:
2.1.x :white_check_mark:
< 2.1.x :x:

Reporting a Vulnerability

Security Vulnerability Disclosure and Response Process

To ensure KubeSphere security, a security vulnerability disclosure and response process is adopted. And the security team is set up in KubeSphere community, also any issue and PR is welcome for every contributors.

The primary goal of this process is to reduce the total exposure time of users to publicly known vulnerabilities. To quickly fix vulnerabilities of KubeSphere, the security team is responsible for the entire vulnerability management process, including internal communication and external disclosure.

If you find a vulnerability or encounter a security incident involving vulnerabilities of KubeSphere, please report it as soon as possible to the KubeSphere security team (security@kubesphere.io).

Please kindly help provide as much vulnerability information as possible in the following format:

  • Issue title(Please add 'Security' lable)*:

  • Overview*:

  • Affected components and version number*:

  • CVE number (if any):

  • Vulnerability verification process*:

  • Contact information*:

The asterisk (*) indicates the required field.

Response Time

The KubeSphere security team will confirm the vulnerabilities and contact you within 2 working days after your submission.

We will publicly thank you after fixing the security vulnerability. To avoid negative impact, please keep the vulnerability confidential until we fix it. We would appreciate it if you could obey the following code of conduct:

The vulnerability will not be disclosed until KubeSphere releases a patch for it.

The details of the vulnerability, for example, exploits code, will not be disclosed.

Go
1
https://gitee.com/fyyc1204/kubesphere.git
git@gitee.com:fyyc1204/kubesphere.git
fyyc1204
kubesphere
kubesphere
master

搜索帮助

53164aa7 5694891 3bd8fe86 5694891