Skip to content

Commit

Permalink
Merge pull request #130 from AkihiroSuda/remove-security-mailing-list
Browse files Browse the repository at this point in the history
SECURITY.md: remove references to security@containerd.io
  • Loading branch information
dmcgowan authored Oct 15, 2024
2 parents b50f5a9 + 5b1ee5a commit 6d5d6d4
Showing 1 changed file with 10 additions and 16 deletions.
26 changes: 10 additions & 16 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,21 +2,16 @@

## Reporting a Vulnerability

To report a containerd vulnerability, either:
To report a containerd vulnerability:

1. Report it on Github directly:
* Navigate to the security tab on the repository
![Github Security Tab](./img/Security-Tab.png)

Navigate to the security tab on the repository
![Github Security Tab](./img/Security-Tab.png)
* Click on `Advisories`
![Github Advisories tab](./img/Advisories.png)

Click on 'Advisories'
![Github Advisories tab](./img/Advisories.png)

Click on 'Report a vulnerability'
![Report a vulnerability](./img/Report-A-Vulnerability.png)

2. Send an email to `security@containerd.io` detailing the issue and steps
to reproduce.
* Click on `Report a vulnerability`
![Report a vulnerability](./img/Report-A-Vulnerability.png)

The reporter(s) can expect a response within 24 hours acknowledging
the issue was received. If a response is not received within 24 hours, please
Expand Down Expand Up @@ -57,7 +52,6 @@ the security announce mailing list. Indirect users who use containerd through a
vendor are not expected to join, but should request their vendor join. To join
the mailing list, the individual or organization must be sponsored by either a
containerd committer or security advisor as well as have a record of properly
handling non-public security information. If a sponsor cannot be found,
sponsorship may be requested at `security@containerd.io`. Sponsorship should not
be requested via public channels since membership of the security announce list
is not public.
handling non-public security information.
Sponsorship should not be requested via public channels since membership of the
security announce list is not public.

0 comments on commit 6d5d6d4

Please sign in to comment.