https://github.com/kubernetes/committee-security-response
Kubernetes Security Process and Security Committee docs
https://github.com/kubernetes/committee-security-response
Last synced: about 1 year ago
JSON representation
Kubernetes Security Process and Security Committee docs
- Host: GitHub
- URL: https://github.com/kubernetes/committee-security-response
- Owner: kubernetes
- License: apache-2.0
- Created: 2019-02-22T22:18:03.000Z (over 7 years ago)
- Default Branch: main
- Last Pushed: 2025-04-24T19:22:31.000Z (about 1 year ago)
- Last Synced: 2025-04-24T20:32:05.419Z (about 1 year ago)
- Language: Python
- Size: 765 KB
- Stars: 173
- Watchers: 20
- Forks: 67
- Open Issues: 13
-
Metadata Files:
- Readme: README.md
- Contributing: CONTRIBUTING.md
- License: LICENSE
- Code of conduct: code-of-conduct.md
- Security: SECURITY.md
Awesome Lists containing this project
README
# Security
Kubernetes Security Release Process and Security Committee documentation.
To report a vulnerability, please refer to https://kubernetes.io/security.
## Security Response Committee (SRC)
The Security Response Committee (SRC) is responsible for triaging and handling the security issues for Kubernetes. Following are the current Security Response Committee members:
- Adolfo García Veytia (**[@puerco](https://github.com/puerco)**) ``
- CJ Cullen (**[@cjcullen](https://github.com/cjcullen)**) ``
- Craig Ingram (**[@cji](https://github.com/cji)**) ``
- Joel Smith (**[@joelsmith](https://github.com/joelsmith)**) `` [4096R/0x1688ADC79BECDDAF]
- Micah Hausler (**[@micahhausler](https://github.com/micahhausler)**) ``
- Mo Khan (**[@enj](https://github.com/enj)**) ``
- Rita Zhang (**[@ritazh](https://github.com/ritazh)**) ``
- Nathan Herz (**[@natherz97](https://github.com/natherz97)**) ``
- Sri Saran Balaji (**[@SaranBalaji90](https://github.com/SaranBalaji90)**) ``
- Tabitha Sable (**[@tabbysable](https://github.com/tabbysable)**) ``
- Vyom Yadav (**[@Vyom-Yadav](https://github.com/Vyom-Yadav)**) ``
### Contacting the SRC
There are a number of contact points for the SRC and release managers in charge of security releases. Please use the correct forum for the best and fastest response.
| List or Group | Visibility | Uses |
| ------------- | ---------- | ---- |
| security@kubernetes.io | Private | Kubernetes security disclosures. This list is closely monitored and triaged by the SRC. [See the disclosure guide for full details.](http://kubernetes.io/security) |
| [kubernetes-security-discuss Google Group](https://groups.google.com/forum/#!forum/kubernetes-security-discuss) | Public | Discussion about security disclosure handling, this document, and other updates. |
| release-managers-private@kubernetes.io | Private | Release Managers private discussion. All members are subscribed to security@kubernetes.io. |
| security-discuss-private@kubernetes.io | Private | SRC private discussion. All members are subscribed to security@kubernetes.io |
## Community, discussion, contribution, and support
Learn how to engage with the Kubernetes community on the [community page](http://kubernetes.io/community/).
### Code of conduct
Participation in the Kubernetes community is governed by the [Kubernetes Code of Conduct](code-of-conduct.md).