Artifact Hub · Vulnerability Disclosure
Artifact Hub Vulnerability Disclosure
Vulnerability disclosure
Artifact Hub publishes a named security contact and a written, staged remediation process. It is NOT discoverable the standard way: there is no /.well-known/security.txt — every /.well-known/ path on artifacthub.io returns the SPA shell (see well-known/artifact-hub-well-known.yml). The policy lives only in the GitHub repository, so a scanner looking at the domain finds nothing.
Artifact Hub runs a coordinated vulnerability disclosure program on Hackerone.
Cloud-NativeCNCFHelm ChartsPackage RegistryDiscoveryOpen-Source
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.