Add information about security

Versions that will receive security fixes, and
how to report vulnerabilities to the maintainers.

Signed-off-by: James Hewitt <james.hewitt@uk.ibm.com>
This commit is contained in:
James Hewitt 2022-09-22 23:40:10 +01:00
parent 29b5e79f82
commit 7e51e717fb
No known key found for this signature in database
GPG Key ID: EA6C3C654B6193E4
1 changed files with 15 additions and 0 deletions

15
SECURITY.md Normal file
View File

@ -0,0 +1,15 @@
# Security Policy
## Supported Versions
These versions are currently receiving security updates.
| Version | Supported |
| ------- | ------------------ |
| 3.0.x | :white_check_mark: |
| 2.7.x | :white_check_mark: |
| < 2.7 | :x: |
## Reporting a Vulnerability
To report a security disclosure, emails the project maintainers on the maintainer mailing list: cncf-distribution-maintainers@lists.cncf.io