Cloud Native Buildpacks · Vulnerability Disclosure

Buildpacks Vulnerability Disclosure

Vulnerability disclosure

Cloud Native Buildpacks publishes a full coordinated-disclosure policy — reporting channels, a PGP key, an acknowledgment SLA, a defined response process and a public disclosure venue. It is NOT served at /.well-known/security.txt (that path 404s on every host, see well-known/buildpacks-well-known.yml); it lives in the organization-wide .github repository, which is where GitHub surfaces it on every buildpacks/* repo's Security tab.

Cloud Native Buildpacks runs a coordinated vulnerability disclosure program on Hackerone.

Build ToolsCI/CDCloud-NativeCNCFContainer ImagesContainersOCIOpen-Source
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-05'
method: searched
source: https://github.com/buildpacks/.github/blob/main/SECURITY.md
provider: Cloud Native Buildpacks
providerId: buildpacks
published: true
policy_url: https://github.com/buildpacks/.github/blob/main/SECURITY.md
description: >-
  Cloud Native Buildpacks publishes a full coordinated-disclosure policy — reporting channels, a
  PGP key, an acknowledgment SLA, a defined response process and a public disclosure venue. It is
  NOT served at /.well-known/security.txt (that path 404s on every host, see
  well-known/buildpacks-well-known.yml); it lives in the organization-wide .github repository, which
  is where GitHub surfaces it on every buildpacks/* repo's Security tab.
reporting:
  channels:
  - type: github-security-advisory
    url: https://github.com/buildpacks/community/security/advisories/new
  - type: email
    address: security@buildpacks.io
    pgp_fingerprint: 7AA4 452E A0C3 56F8 894D C869 4E56 F857 5412 6F64
    pgp_keyserver: pgp.mit.edu
  scope_note: >-
    "These channels should only be used for reporting undisclosed security vulnerabilities in Cloud
    Native Buildpacks products." Regular bug reports are explicitly out of scope.
  requested_content:
  - affected software and versions
  - steps to reproduce
  - impact / potential consequences
  - suggested severity
  - logs, screenshots or proof-of-concept code
response_process:
  acknowledgment_sla: 72 hours
  steps:
  - Acknowledgment within 72 hours by the security team.
  - Triage — a maintainer is assigned to investigate and validate, contacting the reporter directly if more is needed.
  - Advisory draft — a draft GitHub Security Advisory is created to coordinate with reporter and maintainers.
  - Fix development in private; patch and disclosure dates agreed with the reporter.
  - Disclosure once the fix ships, via GitHub Security Advisories and project release notes.
  coordinated_disclosure: true
  embargo: negotiated with the reporter rather than fixed
public_disclosure:
  venues:
  - https://github.com/buildpacks/community/security/advisories
  - project release notes
supported_versions:
  policy: >-
    "Security fixes are applied to the latest release of each Cloud Native Buildpacks project. Users
    are encouraged to stay on the most recent release to receive security updates."
  backports: false
bug_bounty:
  offered: false
  note: >-
    No HackerOne, Bugcrowd or Intigriti program was found. probe-security-programs.py reported
    vdp=none trust=none on 2026-09-05 because it looks for a security.txt / bounty page rather than
    an org .github SECURITY.md — the policy is real, the automated probe simply misses this shape.
audits:
- type: third-party security audit
  date: '2024-07-17'
  auditor: Quarkslab, funded by the CNCF and coordinated by OSTIF
  report: https://ostif.org/buildpacks-audit-complete/
- type: CNCF security self-assessment
  date: '2021-09-07'
  note: Filed in the cncf/toc repository as part of the incubation process.
badges:
- name: OpenSSF (CII) Best Practices
  url: https://bestpractices.coreinfrastructure.org/projects/4748

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/buildpacks-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.