Skip to content

Add SECURITY.md security policy - #2371

Merged
thomasferrandiz merged 3 commits into
masterfrom
add-security-policy
Mar 11, 2026
Merged

Add SECURITY.md security policy#2371
thomasferrandiz merged 3 commits into
masterfrom
add-security-policy

Conversation

@pgonin

@pgonin pgonin commented Mar 5, 2026

Copy link
Copy Markdown
Member

Summary

Adds a SECURITY.md file at the repository root to document the flannel project's vulnerability reporting and disclosure process.

Closes #2370

What this adds

  • Supported versions table
  • Private reporting channel via GitHub vulnerability reporting
  • Coordinated disclosure process with explicit timeframes (7-day acknowledgement, 90-day resolution target)
  • Scope definition (in/out of scope)
  • Security-related deployment guidance

OpenSSF Scorecard impact

This brings the Security-Policy score from 0/10 to 10/10 on the OpenSSF Scorecard.

Closes #2370

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
@thomasferrandiz
thomasferrandiz merged commit c9e51ab into master Mar 11, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add Security Policy (SECURITY.md) to improve OpenSSF Scorecard

3 participants