Skip to content

Commit

Permalink
Add a blurb to SECURITY.md about CVE scanners
Browse files Browse the repository at this point in the history
  • Loading branch information
tianon committed Apr 27, 2023
1 parent 3d9ab3e commit 2933505
Showing 1 changed file with 3 additions and 1 deletion.
4 changes: 3 additions & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
# Security Policy

If you believe you have found a security vulnerability, please make every effort to report it to the appropriate maintainers responsibly so that it can be fixed discreetly (also known as "embargo").
If you have run a CVE/security scanner on an image and that is why you are here, you should read [our "Why does my security scanner show that an image has CVEs?" FAQ entry](https://github.com/docker-library/faq#why-does-my-security-scanner-show-that-an-image-has-cves).

If you believe you have found a net new security vulnerability, please make every effort to report it to the appropriate maintainers responsibly so that it can be fixed discreetly (also known as "embargo").

When the issue relates to a specific image, please make an effort to (privately) contact the maintainers of that specific image. Some maintainers publish/maintain a `SECRUITY.md` in their GitHub repository, for example, which can be a great place to find information about how to report an issue appropriately.

Expand Down

0 comments on commit 2933505

Please sign in to comment.