forked from dragonflyoss/dragonfly
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathSECURITY-INSIGHTS.yml
More file actions
64 lines (61 loc) · 2.32 KB
/
Copy pathSECURITY-INSIGHTS.yml
File metadata and controls
64 lines (61 loc) · 2.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
# Security Insights for DragonflyOSS/Dragonfly
# This file adheres to the OSSF Security Insights Specification v2.0.0
header:
schema-version: 2.0.0
last-updated: "2025-07-15"
last-reviewed: "2025-07-15"
url: https://github.com/dragonflyoss/dragonfly
comment: |
Security insights for the Dragonfly P2P-based file distribution and image acceleration system.
project:
name: Dragonfly
homepage: https://d7y.io/
administrators:
- name: Dragonfly Maintainers
affiliation: Cloud Native Computing Foundation (CNCF)
email: dragonfly-maintainers@googlegroups.com
primary: true
repositories:
- name: dragonfly
url: https://github.com/dragonflyoss/dragonfly
comment: |
Main repository for Dragonfly P2P-based file distribution and image acceleration system.
vulnerability-reporting:
reports-accepted: true
bug-bounty-available: false
security-policy: https://github.com/dragonflyoss/dragonfly/blob/main/SECURITY.md
contact:
name: Dragonfly Security Team
affiliation: Cloud Native Computing Foundation (CNCF)
email: dragonfly-maintainers@googlegroups.com
primary: true
documentation:
code-of-conduct: https://github.com/dragonflyoss/community/blob/master/CODE_OF_CONDUCT.md
repository:
url: https://github.com/dragonflyoss/dragonfly
status: active
accepts-change-request: true
accepts-automated-change-request: true
core-team:
- name: Dragonfly Maintainers
affiliation: Cloud Native Computing Foundation (CNCF)
email: dragonfly-maintainers@googlegroups.com
primary: true
license:
url: https://github.com/dragonflyoss/dragonfly/blob/main/LICENSE
expression: Apache-2.0
security:
assessments:
self:
comment: |
Dragonfly undergoes regular security assessments as part of CNCF graduated project requirements.
The project follows CNCF security best practices and guidelines.
date: "2025-07-15"
documentation:
contributing-guide: https://github.com/dragonflyoss/community/blob/master/CONTRIBUTING.md
security-policy: https://github.com/dragonflyoss/dragonfly/blob/main/SECURITY.md
release:
automated-pipeline: true
distribution-points:
- uri: https://github.com/dragonflyoss/dragonfly/releases
comment: GitHub releases page with binaries and release notes