Skip to content

Commit 721b999

Browse files
committed
Add security insights link
Signed-off-by: zhujian <[email protected]>
1 parent adf4455 commit 721b999

File tree

1 file changed

+2
-4
lines changed

1 file changed

+2
-4
lines changed

SELF_ASSESSMENT.md

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ This document evaluates the security posture of the Open Cluster Management (OCM
3535
| Security Provider? | No. OCM is designed to enable end-to-end visibility and control across multiple Kubernetes clusters. Security is not the primary objective.|
3636
| Languages | Go, Shell, Python, Makefile, Dockerfile |
3737
| Software Bill of Materials | [FOSSA Scan](https://app.fossa.com/projects/git%2Bgithub.com%2Fopen-cluster-management-io%2Focm/refs/branch/main/c05247840ad6e69cad82f7d42e2217b953181dff/preview) |
38-
| Security Links | [Security Report](https://open-cluster-management.io/docs/security/)<br>Creation of a security-insights.yml is planned and will be addressed in upcoming releases. |
38+
| Security Links | [Security Report](https://open-cluster-management.io/docs/security/)<br>[Security Insights](./SECURITY-INSIGHTS.yml) |
3939

4040
## Overview
4141

@@ -205,8 +205,6 @@ The OCM security policy is maintained in the website [Security page](https://ope
205205

206206
The OCM project accepts vulnerability reports through the email [[email protected]](mailto:[email protected]), a maintainer will collaborate directly with the reporter through the email or Slack direct message until it is resolved.
207207

208-
TODO: Consider [enabling the GitHub private vulnerability reporting](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability).
209-
210208
### Incident Response
211209

212210
In the event that a vulnerability is reported, the maintainer team will collaborate to determine the validity and criticality of the report. Based on these findings, the fix will be triaged and the maintainer team will work to issue a patch in a timely manner.
@@ -220,7 +218,7 @@ Patches will be made to the most recent three minor releases. Information will b
220218
- OpenSSF Best Practices
221219
- OCM has attained the Open Source Security Foundation(OpenSSF) Best Practices Badge, refer to https://bestpractices.coreinfrastructure.org/projects/5376.
222220
- Case Studies
223-
- All apoters can be found at [adopters-list](https://github.com/open-cluster-management-io/ocm/blob/main/ADOPTERS.md).
221+
- All adopters can be found at [adopters-list](https://github.com/open-cluster-management-io/ocm/blob/main/ADOPTERS.md).
224222
- TODO: Add 2 examples
225223
- Related Projects / Vendors
226224
- **Karmada**: [Karmada](https://karmada.io/) (Kubernetes Armada) is a Kubernetes management system that can manage cloud-native applications across multiple Kubernetes clusters and clouds, with no changes to the applications.

0 commit comments

Comments
 (0)