Cloud Native Buildpacks · Vulnerability Disclosure
Buildpacks Vulnerability Disclosure
Vulnerability disclosure
Cloud Native Buildpacks publishes a full coordinated-disclosure policy — reporting channels, a PGP key, an acknowledgment SLA, a defined response process and a public disclosure venue. It is NOT served at /.well-known/security.txt (that path 404s on every host, see well-known/buildpacks-well-known.yml); it lives in the organization-wide .github repository, which is where GitHub surfaces it on every buildpacks/* repo's Security tab.
Cloud Native Buildpacks runs a coordinated vulnerability disclosure program on Hackerone.
Build ToolsCI/CDCloud-NativeCNCFContainer ImagesContainersOCIOpen-Source
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.