Commit Graph

5 Commits

Author SHA1 Message Date
EndlessSeeker
fa9c096a7d docs: update SECURITY.md and CODE_OF_CONDUCT.md reporting channels
- SECURITY.md: require reporting to both GitHub Private Security Advisory
  and ASRC, remove email channel
- CODE_OF_CONDUCT.md: unify reporting to CNCF CoC Committee (conduct@cncf.io),
  add reference to CNCF Incident Resolution Procedures

Change-Id: I771880e9c488247f015dda4ecb0dac95be29fef1
Co-developed-by: Kiro <noreply@kiro.dev>
Signed-off-by: EndlessSeeker <1766508902@qq.com>
2026-04-28 16:45:35 +08:00
EndlessSeeker
5b64f2112d docs: add ASRC as supplementary vulnerability reporting channel in SECURITY.md
Change-Id: I52297cb7169a9997be08e8d4c69db599113d960a
Co-developed-by: Kiro <noreply@kiro.dev>
Signed-off-by: EndlessSeeker <1766508902@qq.com>
2026-04-28 16:24:10 +08:00
EndlessSeeker
3e84ff3537 docs: update SECURITY.md, CONTRIBUTING docs, and remove OpenSSF badge placeholder
- SECURITY.md: formalize vulnerability reporting process with GitHub Private
  Security Advisory and email channels, add response SLA (3-day ack, 14-day
  triage, 90-day disclosure), add security response team and disclosure policy
- CONTRIBUTING_EN/CN/JP.md: add test requirements for new functionality
  (30% plugin coverage gate, 50% patch coverage), link security reporting
  to SECURITY.md
- README/README_ZH/README_JP: remove OpenSSF Best Practices badge placeholder
  until passing badge is achieved

Change-Id: Ice19b163c48dab73c903a0b9f4c33ddeff892ebb
Co-developed-by: Kiro <noreply@kiro.dev>
Signed-off-by: EndlessSeeker <1766508902@qq.com>
2026-04-28 15:55:27 +08:00
澄潭
d0693d8c4b Update SECURITY.md 2024-10-16 11:17:44 +08:00
澄潭
87366aab49 Create SECURITY.md 2023-03-29 10:00:31 +08:00