-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Expand file tree
/
Copy pathSECURITY-INSIGHTS.yml
More file actions
101 lines (99 loc) · 3.06 KB
/
Copy pathSECURITY-INSIGHTS.yml
File metadata and controls
101 lines (99 loc) · 3.06 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
header:
schema-version: 2.2.0
last-updated: '2026-09-02'
last-reviewed: '2026-09-02'
url: https://github.com/velero-io/velero/blob/main/SECURITY-INSIGHTS.yml
comment: |
OpenSSF Security Insights manifest for the Velero project.
project:
name: Velero
homepage: https://velero.io
roadmap: https://github.com/velero-io/velero/blob/main/ROADMAP.md
administrators:
- name: Scott Seago
affiliation: Red Hat
primary: false
- name: Daniel Jiang
affiliation: Broadcom
primary: true
- name: Wenkai Yin
affiliation: Broadcom
primary: false
- name: Xun Jiang
affiliation: Broadcom
primary: false
- name: Shubham Pampattiwar
affiliation: Red Hat
primary: false
- name: Yonghui Li
affiliation: Broadcom
primary: false
- name: Anshul Ahuja
affiliation: Microsoft Azure
primary: false
- name: Tiger Kaovilai
affiliation: Red Hat
primary: false
documentation:
detailed-guide: https://velero.io/docs/
repositories:
- name: velero
url: https://github.com/velero-io/velero
comment: |
velero is the core repository for the Velero project.
vulnerability-reporting:
reports-accepted: true
bug-bounty-available: false
contact:
name: Velero Security Team
email: cncf-velero-security@lists.cncf.io
primary: true
comment: |
Report vulnerabilities privately to the Velero Security Team by email or
via GitHub private vulnerability reporting on the repository Security tab.
See the security policy for full details.
repository:
url: https://github.com/velero-io/velero
status: active
accepts-change-request: true
accepts-automated-change-request: true
core-team:
- name: Scott Seago
affiliation: Red Hat
primary: false
- name: Daniel Jiang
affiliation: Broadcom
primary: true
- name: Wenkai Yin
affiliation: Broadcom
primary: false
- name: Xun Jiang
affiliation: Broadcom
primary: false
- name: Shubham Pampattiwar
affiliation: Red Hat
primary: false
- name: Yonghui Li
affiliation: Broadcom
primary: false
- name: Anshul Ahuja
affiliation: Microsoft Azure
primary: false
- name: Tiger Kaovilai
affiliation: Red Hat
primary: false
license:
url: https://github.com/velero-io/velero/blob/main/LICENSE
expression: Apache-2.0
documentation:
contributing-guide: https://velero.io/docs/main/start-contributing/
governance: https://github.com/velero-io/.github/blob/main/GOVERNANCE.md
security-policy: https://github.com/velero-io/.github/blob/main/SECURITY.md
dependency-management-policy: https://github.com/velero-io/velero/blob/main/site/content/docs/main/development.md#dependency-management
security:
assessments:
self:
comment: |
A formal third-party security assessment has not yet been completed.
The project follows the CNCF security disclosure and response process
documented in the security policy.