Skip to content

docs: add SECURITY.md with private vulnerability reporting policy - #29

Merged
dcmcand merged 1 commit into
mainfrom
docs/security-policy
Oct 9, 2026
Merged

dcmcand merged 1 commit into
mainfrom
docs/security-policy

Conversation

@dcmcand

@dcmcand dcmcand commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds a SECURITY.md so the repo's Security tab and GitHub's "Report a vulnerability" flow point reporters to a documented policy. GitHub private vulnerability reporting has been enabled on this repo, and the policy directs reports there instead of public issues.

The policy covers supported versions (latest release only), how to report and what to include, what reporters can expect, and what is in and out of scope for this repo. Repos whose Helm chart is published to quay.io/nebari/charts also get a cosign verify command for the chart signature, linking to the org-wide Verifying Nebari artifacts guide for the rest.

This matches the policy added to Nebari Infrastructure Core in nebari-dev/nebari-infrastructure-core#703.

How to Test

Render SECURITY.md on the branch and check the links. Where a "Verifying Releases" section is present, run the cosign verify command against the chart's latest published version; it was run against each chart's latest version on quay.io and passes.

@dcmcand
dcmcand merged commit 4bcbfcf into main Oct 9, 2026
6 checks passed
@dcmcand
dcmcand deleted the docs/security-policy branch October 9, 2026 10:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant