| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
This document defines security reporting, handling, disclosure, and audit information for the Flux project and community.
Also see our Flux Security documentation landing page for an overview of project security information geared toward end users.
We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the Flux community.
Current Security Team members:
| Name | GitHub | Key URL | Fingerprint |
|---|---|---|---|
| Hidde Beydals | @hiddeco | https://keybase.io/hidde/pgp_keys.asc | C910 7A9B 55A4 DD77 062B 9731 B6E3 6A6A C54A CD59 |
| Matheus Pimenta | @matheuscscp | https://keybase.io/matheuscscp/pgp_keys.asc | B404 C733 A16F 589B 592A 4FD7 86D8 78C7 79EB 9A95 |
| Stefan Prodan | @stefanprodan | https://keybase.io/stefanprodan/pgp_keys.asc | 613B F2C4 D985 BBCB 1474 123F 5A00 A045 0068 3EBD |
| Scott Rigby | @scottrigby | https://keybase.io/r6by/pgp_keys.asc | 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 |
Vulnerability disclosures are emailed to the Flux Dev mailing list https://lists.cncf.io/g/cncf-flux-dev and announced publicly. Disclosures will contain an overview, details about the vulnerability, a fix that will typically be an update, and optionally a workaround if one is available.
We will coordinate publishing disclosures and security releases in a way that is realistic and necessary for end users. We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available. Disclosures will always be published in a timely manner after a release is published that fixes the vulnerability.
The Flux security team publishes its advisories directly into the affected repositories. The main exception to this rule is flux2, which aggregates the CVEs across all Flux components (CLI and controllers).
The existing advisories can be found below:
| Back | FazBrowse Home | New Git URL |