Security fixes are prioritized for the latest released version on main.
Please report vulnerabilities privately using one of these channels:
- GitHub Security Advisory (preferred): use "Report a vulnerability" in the repository Security tab.
- If Security Advisories are unavailable, open a private contact request with maintainers in the organization.
Do not open a public issue for suspected vulnerabilities.
Please include:
- Affected version/tag and deployment mode (CLI, CI gate, admission webhook).
- Reproduction steps or proof-of-concept.
- Impact assessment (confidentiality/integrity/availability).
- Any relevant logs, certificate IDs, and traces.
Best-effort targets:
- Initial triage response within 3 business days.
- Severity assessment and remediation plan within 7 business days.
- Coordinated disclosure timeline agreed with the reporter.
Once fixed, maintainers will publish a release note including:
- Affected versions.
- Mitigation/upgrade guidance.
- Credit to reporter (if requested).