forked from k8gb-io/k8gb
-
Notifications
You must be signed in to change notification settings - Fork 0
/
SECURITY-INSIGHTS.yml
79 lines (71 loc) · 2.4 KB
/
SECURITY-INSIGHTS.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
header:
schema-version: 1.0.0
expiration-date: '2024-12-31T23:23:59.000Z'
last-updated: '2023-10-26'
last-reviewed: '2022-10-26'
commit-hash: d01f1a8e2c9918c15b8e640f9be86a4c0be46c9d
project-url: https://github.com/k8gb-io/k8gb
project-release: '0.14.0'
changelog: https://github.com/k8gb-io/k8gb/blob/master/CHANGELOG.md
license: https://github.com/k8gb-io/k8gb/blob/master/LICENSE.md
project-lifecycle:
status: active
roadmap: https://github.com/orgs/k8gb-io/projects/2/views/2
bug-fixes-only: false
core-maintainers:
- https://github.com/jkremser
- https://github.com/k0da
- https://github.com/kuritka
- https://github.com/ytsarev
- https://github.com/somaritane
release-cycle: https://github.com/k8gb-io/k8gb/blob/master/CONTRIBUTING.md#release-process
release-process: |
Fully automated & pull-request based
contribution-policy:
accepts-pull-requests: true
accepts-automated-pull-requests: true
automated-tools-list:
- automated-tool: renovate
action: allowed
path:
- .github/workflows
- go.mod
- go.sum
- Dockerfile
- chart/k8gb/values.yaml
contributing-policy: https://github.com/k8gb-io/k8gb/blob/master/CONTRIBUTING.md
code-of-conduct: https://github.com/k8gb-io/k8gb/blob/master/CODE_OF_CONDUCT.md
documentation:
- https://www.k8gb.io/docs/
distribution-points:
- https://github.com/k8gb-io/k8gb/releases
- https://hub.docker.com/r/absaoss/k8gb/tags
security-artifacts:
self-assessment:
self-assessment-created: true
evidence-url:
- https://github.com/k8gb-io/k8gb/blob/master/self-assessment.md
comment: |
Created on 2023-10-31
security-contacts:
- type: email
value: cncf-k8gb-maintainers@lists.cncf.io
primary: true
- type: email
value: yury@upbound.io
primary: false
vulnerability-reporting:
accepts-vulnerability-reports: true
email-contact: cncf-k8gb-maintainers@lists.cncf.io
security-policy: https://github.com/k8gb-io/k8gb/blob/master/SECURITY.md
bug-bounty-available: false
dependencies:
third-party-packages: true
dependencies-lists:
- https://github.com/k8gb-io/k8gb/blob/master/go.mod
env-dependencies-policy:
policy-url: https://github.com/k8gb-io/k8gb/blob/main/DEPENDENCY.md
sbom:
- sbom-file: https://github.com/k8gb-io/k8gb/releases/download/v0.14.0/k8gb_0.14.0_linux_amd64.tar.gz.sbom.json
sbom-format: SPDX
sbom-url: https://github.com/k8gb-io/k8gb/releases/