Skip to content

Commit 1619bf8

Browse files
committed
Security Policy for eksctl project
1 parent eae8392 commit 1619bf8

File tree

2 files changed

+18
-0
lines changed

2 files changed

+18
-0
lines changed

README.md

+6
Original file line numberDiff line numberDiff line change
@@ -199,6 +199,12 @@ Minor releases of `eksctl` should be expected every two weeks and patch releases
199199

200200
One or more release candidate(s) (RC) builds will be made available prior to each minor release. RC builds are intended only for testing purposes.
201201

202+
## [Security Policy](SECURITY.md)
203+
If you discover a potential security issue in `eksctl` project, please
204+
follow [AWS Vulnerability Reporting process.](https://aws.amazon.com/security/vulnerability-reporting/)
205+
206+
Do not open security related issues in the open source project.
207+
202208
## Get in touch
203209

204210
[Create an issue](https://github.com/weaveworks/eksctl/issues/new), or login to [Weave Community Slack (#eksctl)][slackchan] ([signup][slackjoin]).

SECURITY.md

+12
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
# Security Policy
2+
3+
## Reporting a Vulnerability
4+
5+
If you discover a potential security issue in `eksctl` project, please
6+
follow [AWS Vulnerability Reporting process.](https://aws.amazon.com/security/vulnerability-reporting/)
7+
8+
Do not open security related issues in the open source project. So that we may more effectively respond to your report, please provide any supporting material (proof-of-concept code, tool output, etc.) that would be useful in helping us understand the nature and severity of the vulnerability.
9+
10+
The information you share with AWS as part of this process is kept confidential within AWS. AWS will only share this information with a third party if the vulnerability you report is found to affect a third-party product, in which case we will share this information with the third-party product's author or manufacturer. Otherwise, AWS will only share this information as permitted by you.
11+
12+
AWS is committed to being responsive and keeping you informed of our progress as we investigate and / or mitigate your reported security concern. You will receive a non-automated response to your initial contact within 24 hours, confirming receipt of your reported vulnerability. You will receive progress updates from AWS at least every five US working days.

0 commit comments

Comments
 (0)