Files
open-cluster-management/SECURITY-INSIGHTS.yml
Jian Zhu 61c8d7f06b
Some checks failed
Scorecard supply-chain security / Scorecard analysis (push) Failing after 2m4s
Post / coverage (push) Failing after 36m57s
Post / images (amd64) (push) Failing after 9m7s
Post / images (arm64) (push) Failing after 8m19s
Post / image manifest (push) Has been skipped
Post / trigger clusteradm e2e (push) Has been skipped
Close stale issues and PRs / stale (push) Successful in 1m18s
Update SECURITY-INSIGHTS.yml (#1070)
Signed-off-by: zhujian <jiazhu@redhat.com>
2025-07-15 09:23:59 +00:00

63 lines
2.3 KiB
YAML

header:
schema-version: '1.0.0'
last-updated: '2025-07-14'
last-reviewed: '2025-07-14'
expiration-date: '2026-07-14T01:00:00.000Z'
project-url: 'https://github.com/open-cluster-management-io/ocm'
project-release: '1.0.0'
changelog: 'https://github.com/open-cluster-management-io/ocm/releases'
license: 'https://github.com/open-cluster-management-io/ocm/blob/main/LICENSE'
project-lifecycle:
status: active
bug-fixes-only: false
core-maintainers:
- 'https://github.com/open-cluster-management-io/community/blob/main/MAINTAINERS.md'
roadmap: 'https://open-cluster-management.io/docs/roadmap'
release-process: 'https://github.com/open-cluster-management-io/community/blob/main/RELEASE.md'
contribution-policy:
accepts-pull-requests: true
accepts-automated-pull-requests: true
code-of-conduct: 'https://github.com/open-cluster-management-io/community/blob/main/CODE_OF_CONDUCT.md'
contributing-policy: 'https://open-cluster-management.io/docs/contribution-guidelines'
documentation:
- 'https://open-cluster-management.io'
distribution-points:
- 'https://github.com/open-cluster-management-io/ocm/releases'
- 'https://quay.io/organization/open-cluster-management'
- 'https://open-cluster-management.io/helm-charts'
security-artifacts:
self-assessment:
self-assessment-created: true
evidence-url:
- 'https://github.com/open-cluster-management-io/ocm/blob/main/SELF_ASSESSMENT.md'
security-testing:
- tool-type: sca
tool-name: Dependabot
tool-version: '2'
tool-url: 'https://github.com/open-cluster-management-io/ocm/blob/main/.github/dependabot.yml'
integration:
ad-hoc: false
ci: true
before-release: true
- tool-type: sca
tool-name: Dependency-Review
tool-version: 'v4.7.1'
tool-url: 'https://github.com/open-cluster-management-io/ocm/blob/main/.github/workflows/dependency-review.yml'
integration:
ad-hoc: false
ci: true
before-release: true
comment: |
Dependency Review checks the dependencies for every PRs.
security-contacts:
- type: email
value: 'OCM-security@googlegroups.com'
vulnerability-reporting:
accepts-vulnerability-reports: true
security-policy: 'https://open-cluster-management.io/docs/security'
email-contact: 'OCM-security@googlegroups.com'
dependencies:
third-party-packages: true
dependencies-lists:
- 'https://github.com/open-cluster-management-io/ocm/blob/main/go.mod'