Update SECURITY.md

updating to include cncf lists for public disclosure

Signed-off-by: Michael Michael michmike@cs.stanford.edu
This commit is contained in:
Michael Michael 2019-09-19 15:29:27 -07:00 committed by GitHub
parent 0300a804c4
commit e908e1c588
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 1 additions and 1 deletions

View File

@ -51,7 +51,7 @@ The Harbor Security Team will respond to vulnerability reports as follows:
8. Once the fix is confirmed, the Security Team will patch the vulnerability in the next patch or minor release, and backport a patch release into all earlier supported releases.
### Fix Disclosure Process
The Security Team publishes an [advisory](https://github.com/goharbor/harbor/security/advisories) to the Harbor community via GitHub. In most cases, additional communication via Slack, Twitter, blog and other channels will assist in educating Harbor users and rolling out the patched release to affected users.
The Security Team publishes an [advisory](https://github.com/goharbor/harbor/security/advisories) to the Harbor community via GitHub. In most cases, additional communication via Slack, Twitter, CNCF lists, blog and other channels will assist in educating Harbor users and rolling out the patched release to affected users.
The Security Team will also publish any mitigating steps users can take until the fix can be applied to their Harbor instances.