Skip to content

Commit

Permalink
Create Security Policy for Jenkins-X project
Browse files Browse the repository at this point in the history
Set up the GitHub security policy
  • Loading branch information
Cosmin Cojocar committed Nov 14, 2019
1 parent d3ceec4 commit 5d1c05e
Showing 1 changed file with 21 additions and 0 deletions.
21 changes: 21 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Security Policy

The Jenkins X project takes security seriously. We make every possible effort to ensure users can adequately secure their automation infrastructure. To that end, we work with Jenkins X platform and app developers, as well as security researchers, to fix security vulnerabilities in Jenkins X in a timely manner, and to improve the security of Jenkins X in general.

## Supported Versions

| Version | Supported |
| ------- | ------------------ |
| 2.0.x | :white_check_mark: |


## Reporting a Vulnerability

If you find a vulnerability in Jenkins X, please report it in the Jenkins CI issue tracker under the [SECURITY](https://issues.jenkins-ci.org/browse/SECURITY) project. **Please do not report security issues in the github tracker.**
This project is configured in such a way that only the reporter and the security team can see the details. By restricting access to this potentially sensitive information, we can work on a fix and deliver it before the method of attack becomes well-known.

If you are unable to report using the above issue tracker, you can also send your report to the private Jenkins Security Team mailing list: [email protected]

## Vulnerabilities in Apps

Whilst the Jenkins X team is not responsible for the quality of third party apps, please still use the above reporting mechanism and we will co-ordinate with the app developer to ensure a fix in a secure maner.

0 comments on commit 5d1c05e

Please sign in to comment.