From 7ab7f2a2c4cfdbc39148cc72f6d129f60d6453f9 Mon Sep 17 00:00:00 2001 From: Anton Gilgur Date: Tue, 5 Mar 2024 21:35:59 -0500 Subject: [PATCH] docs(security): add Draft GHSA option - for ease of use, built-in templates, crediting, single source of truth, etc - as well as consistency with CD: https://github.com/argoproj/argo-cd/blob/a4b50515381bad9d6db316d49d33efae351c6222/SECURITY.md?plain=1#L68 Signed-off-by: Anton Gilgur --- SECURITY.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 02136b30d74c..96d668b849eb 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -6,9 +6,10 @@ If you find a security related bug in Argo Workflows, we kindly ask you for resp disclosure and for giving us appropriate time to react, analyze and develop a fix to mitigate the found security vulnerability. -Please report vulnerabilities by e-mail to the following address: +Please report vulnerabilities by: -* cncf-argo-security@lists.cncf.io +* Opening a draft GitHub Security Advisory: https://github.com/argoproj/argo-workflows/security/advisories/new +* Sending an e-mail to the following address: cncf-argo-security@lists.cncf.io All vulnerabilities and associated information will be treated with full confidentiality.