Buildpacks Io · Vulnerability Disclosure

Buildpacks Io Vulnerability Disclosure

Vulnerability disclosure

Buildpacks Io runs a coordinated vulnerability disclosure program on Hackerone.

Cloud Native BuildpacksContainer ImagesBuild AutomationCNCFOpen SourceDeveloper ToolsOCISpecificationSupply ChainRegistry
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-17'
method: searched
source: https://github.com/buildpacks/.github/blob/main/SECURITY.md
published: true
policy_url: https://github.com/buildpacks/.github/blob/main/SECURITY.md
note: >-
  The project publishes a full coordinated-disclosure policy, but not at /.well-known/security.txt —
  every host in this record 404s that path (see well-known/). The policy is a repository SECURITY.md
  in the buildpacks/.github org-default repository, which GitHub surfaces on the Security tab of
  every buildpacks repo.
contacts:
- type: email
  value: security@buildpacks.io
- type: github-security-advisory
  value: https://github.com/buildpacks/community/security/advisories/new
pgp:
  fingerprint: 7AA4 452E A0C3 56F8 894D C869 4E56 F857 5412 6F64
  keyserver: pgp.mit.edu
process:
  acknowledgement: within 72 hours
  triage: a maintainer is assigned to investigate and validate
  coordination: draft GitHub Security Advisory shared with the reporter
  fix: developed privately; patch and disclosure date agreed with the reporter
  disclosure: published as a GitHub Security Advisory plus project release notes
supported_versions: latest release of each Cloud Native Buildpacks project
bug_bounty:
  offered: false
  note: No HackerOne, Bugcrowd or Intigriti program; disclosure is unpaid and coordinated.
advisories: https://github.com/buildpacks/community/security/advisories
audits:
- type: third-party security audit
  date: '2024-07-17'
  funder: CNCF
  auditor: OSTIF
  report: https://ostif.org/buildpacks-audit-complete/
- type: CNCF self-assessment
  date: '2021-09-07'
  report: https://github.com/hone/toc/blob/master/projects/buildpacks/security-assessment/self-assessment.md
evidence:
- url: https://github.com/buildpacks/.github/blob/main/SECURITY.md
  status: 200
- url: https://buildpacks.io/.well-known/security.txt
  status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/buildpacks-io-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.