diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..912faeba --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,15 @@ +# Security Policy + +## Reporting a Vulnerability + +To report a security issue, please follow the steps below: + +Using GitHub, file a [Private Security Report](https://github.com/canonical/cluster-api-k8s/security/advisories/new) with: +- A description of the issue +- Steps to reproduce the issue +- Affected versions of the `cluster-api-k8s` package +- Any known mitigations for the issue + +The [Ubuntu Security disclosure and embargo policy](https://ubuntu.com/security/disclosure-policy) contains more information about what to expect during this process and our requirements for responsible disclosure. + +Thank you for contributing to the security and integrity of the `cluster-api-k8s`!