Update security-insights.yml

Signed-off-by: Michael Morris <105736419+MichaelMorrisEst@users.noreply.github.com>
pull/5285/head
Michael Morris 3 weeks ago committed by GitHub
parent ed4754ce8f
commit f6f681a1d9
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

@ -6,28 +6,72 @@ header:
comment: | comment: |
This file contains the security insights information for the flux2 project. This file contains the security insights information for the flux2 project.
project: repository:
name: flux2
homepage: https://github.com/fluxcd/flux2
administrators:
- name:
affiliation:
social:
primary:
documentation:
quickstart-guide: https://github.com/fluxcd/flux2/blob/main/README.md
detailed-guide: https://github.com/fluxcd/flux2/blob/main/README.md
code-of-conduct: https://github.com/fluxcd/flux2/blob/main/CODE_OF_CONDUCT.md
repositories:
- name: fluxcd/flux2
url: https://github.com/fluxcd/flux2 url: https://github.com/fluxcd/flux2
status: active
bug-fixes-only: false
accepts-change-request: true
accepts-automated-change-request: true
no-third-party-packages: false
core-team:
- name: Aurel Canciu
affiliation: NexHealth
email: aurel.canciu@nexhealth.com
social: github: @relu, slack: relu
primary: false
- name: Hidde Beydals
affiliation: Independent
email: hidde@hhh.computer
social: github: @hiddeco, slack: hidde
primary: false
- name: Matheus Pimenta
affiliation: ControlPlane
email: matheuscscp@linux.com
social: github: @matheuscscp, slack: matheuscscp
primary: false
- name: Max Jonas Werner
affiliation: Associmates
email: max.werner@associmates.eu
social: github: @makkes, slack: max
primary: false
- name: Paulo Gomes
affiliation: SUSE
email: pjbgf@linux.com
social: github: @pjbgf, slack: pjbgf
primary: false
- name: Sanskar Jaiswal
affiliation: Independent
email: jaiswalsanskar078@gmail.com
social: github: @aryan9600, slack: aryan9600
primary: false
- name: Soule BA
affiliation: ControlPlane
email: bah.soule@gmail.com
social: github: @souleb, slack: souleb
primary: false
- name: Stefan Prodan
affiliation: ControlPlane
email: stefan.prodan@gmail.com
social: github: @stefanprodan, slack: stefanprodan
primary: true
documentation:
contributing-guide: https://github.com/fluxcd/flux2/blob/main/CONTRIBUTING.md
security-policy: https://github.com/fluxcd/flux2/security
license:
url: https://github.com/fluxcd/flux2/blob/main/LICENSE
release:
changelog: https://github.com/fluxcd/flux2/releases
automated-pipeline: true
distribution-points:
- uri: https://github.com/fluxcd/flux2/releases
comment: GitHub Release Page
license:
url: https://github.com/fluxcd/flux2/blob/main/LICENSE
expression: Apache-2.0
security:
assessments:
third-party:
- evidence: https://fluxcd.io/FluxFinalReport-v1.1.pdf
date: '2021-10-18'
comment: | comment: |
Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories and OCI artifacts), and automating updates to configuration when there is new code to deploy. Overview available at https://fluxcd.io/blog/2021/11/flux-security-audit/
vulnerability-reporting:
reports-accepted: true
bug-bounty-available: false
contact:
name:
email:
primary:
security-policy:

Loading…
Cancel
Save