-
Notifications
You must be signed in to change notification settings - Fork 143
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
1 changed file
with
5 additions
and
5 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,22 +1,22 @@ | ||
# tf-controller Security | ||
# Tofu-Controller Security | ||
|
||
This document defines security reporting, handling and disclosure information for the tf-controller project and community. | ||
This document defines security reporting, handling and disclosure information for the Tofu-Controller project and community. | ||
|
||
## Security Process | ||
|
||
### Report a Vulnerability | ||
|
||
We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the tf-controller community. | ||
We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the Tofu-Controller community. | ||
|
||
- To make a report please email the private security list at <[email protected]> with the details. | ||
- To make a report please go to [Tofu-Controller's Security](https://github.com/flux-iac/tofu-controller/security) page and submit the details. | ||
We ask that reporters act in good faith by not disclosing the issue to others. | ||
- The Security Team will investigate the issue as soon as possible and where needed, coordinate a release date with relevant parties. | ||
- You will be able to choose if you want public acknowledgement of your effort and how you would like to be credited. | ||
- Please note that we do not run a bug bounty program and therefore no financial compensation should be expected when reporting a vulnerability. | ||
|
||
### Security Team | ||
|
||
Our Security Team consists of project maintainers and Weaveworks employees. | ||
Our Security Team consists of the Project's maintainers. | ||
|
||
### Handling | ||
|
||
|