Artifact Hub · Vulnerability Disclosure

Artifact Hub Vulnerability Disclosure

Vulnerability disclosure

Artifact Hub publishes a named security contact and a written, staged remediation process. It is NOT discoverable the standard way: there is no /.well-known/security.txt — every /.well-known/ path on artifacthub.io returns the SPA shell (see well-known/artifact-hub-well-known.yml). The policy lives only in the GitHub repository, so a scanner looking at the domain finds nothing.

Artifact Hub runs a coordinated vulnerability disclosure program on Hackerone.

Cloud-NativeCNCFHelm ChartsPackage RegistryDiscoveryOpen-Source
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-04'
method: searched
source: >-
  https://github.com/artifacthub/hub/blob/master/SECURITY.md and
  https://github.com/artifacthub/hub/blob/master/SECURITY-INSIGHTS.yml (both fetched
  2026-09-04, HTTP 200)
provider: Artifact Hub
providerId: artifact-hub
published: true
description: >-
  Artifact Hub publishes a named security contact and a written, staged remediation process.
  It is NOT discoverable the standard way: there is no /.well-known/security.txt — every
  /.well-known/ path on artifacthub.io returns the SPA shell (see
  well-known/artifact-hub-well-known.yml). The policy lives only in the GitHub repository,
  so a scanner looking at the domain finds nothing.
policy:
  url: https://github.com/artifacthub/hub/blob/master/SECURITY.md
  http_status: 200
contacts:
- type: email
  value: cncf-artifacthub-maintainers@lists.cncf.io
  role: Artifact Hub Maintainers Team
  source: SECURITY.md and SECURITY-INSIGHTS.yml security-contacts
accepts_reports: true
security_txt: false
bug_bounty:
  program: false
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti program was found for Artifact Hub or the CNCF project page.
process:
  advisory_platform: GitHub Security Advisories
  cve_assignment: true
  steps:
  - Maintainers evaluate the report to verify the security issue; non-security reports move to GitHub issues.
  - Create a new draft advisory via GitHub Security Advisories.
  - Request a CVE identification number.
  - Collaborate on a private fork inside the GitHub Security Advisory system to fix the issue.
  - Finalize and publish the CVE, merge the change, and cut a new Artifact Hub release including the fix.
  disclosure_model: coordinated
  safe_harbor: not stated
  response_sla: not stated
security_insights:
  published: true
  url: https://github.com/artifacthub/hub/blob/master/SECURITY-INSIGHTS.yml
  schema_version: 1.0.0
  expiration_date: '2024-10-03'
  expired: true
  expired_note: >-
    The OpenSSF Security Insights manifest declares header.expiration-date
    2024-10-3T10:00:00.000Z. That date is nearly two years past as of 2026-09-04, so by the
    specification's own rules the document is stale and its assertions should not be relied
    on without re-confirmation — even though the security contact it names is still the one
    SECURITY.md gives.
  project_lifecycle: active
  accepts_vulnerability_reports: true
  distribution_point: https://artifacthub.io/packages/helm/artifact-hub/artifact-hub
  core_maintainers:
  - https://github.com/tegioz
  - https://github.com/cynthia-sg
  - https://github.com/mattfarina
  dependencies_policy: https://github.com/artifacthub/hub/blob/master/CONTRIBUTING.md#dependencies-policy
related_security_posture:
  clomonitor: >-
    The repository carries a .clomonitor.yml, so the project is tracked by the CNCF CLOMonitor
    open-source health checker.
  product_security_feature: >-
    Distinct from this policy: Artifact Hub itself SCANS the packages it lists using Trivy and
    publishes the reports (https://artifacthub.io/docs/topics/security_report/, operation
    getPackageSecurityReport). That is a product capability, not a disclosure program, and is
    recorded here only so the two are not confused.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/artifact-hub-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.