generated: '2026-09-04' method: searched source: >- https://github.com/artifacthub/hub/blob/master/SECURITY.md and https://github.com/artifacthub/hub/blob/master/SECURITY-INSIGHTS.yml (both fetched 2026-09-04, HTTP 200) provider: Artifact Hub providerId: artifact-hub published: true description: >- Artifact Hub publishes a named security contact and a written, staged remediation process. It is NOT discoverable the standard way: there is no /.well-known/security.txt — every /.well-known/ path on artifacthub.io returns the SPA shell (see well-known/artifact-hub-well-known.yml). The policy lives only in the GitHub repository, so a scanner looking at the domain finds nothing. policy: url: https://github.com/artifacthub/hub/blob/master/SECURITY.md http_status: 200 contacts: - type: email value: cncf-artifacthub-maintainers@lists.cncf.io role: Artifact Hub Maintainers Team source: SECURITY.md and SECURITY-INSIGHTS.yml security-contacts accepts_reports: true security_txt: false bug_bounty: program: false platform: null note: No HackerOne, Bugcrowd or Intigriti program was found for Artifact Hub or the CNCF project page. process: advisory_platform: GitHub Security Advisories cve_assignment: true steps: - Maintainers evaluate the report to verify the security issue; non-security reports move to GitHub issues. - Create a new draft advisory via GitHub Security Advisories. - Request a CVE identification number. - Collaborate on a private fork inside the GitHub Security Advisory system to fix the issue. - Finalize and publish the CVE, merge the change, and cut a new Artifact Hub release including the fix. disclosure_model: coordinated safe_harbor: not stated response_sla: not stated security_insights: published: true url: https://github.com/artifacthub/hub/blob/master/SECURITY-INSIGHTS.yml schema_version: 1.0.0 expiration_date: '2024-10-03' expired: true expired_note: >- The OpenSSF Security Insights manifest declares header.expiration-date 2024-10-3T10:00:00.000Z. That date is nearly two years past as of 2026-09-04, so by the specification's own rules the document is stale and its assertions should not be relied on without re-confirmation — even though the security contact it names is still the one SECURITY.md gives. project_lifecycle: active accepts_vulnerability_reports: true distribution_point: https://artifacthub.io/packages/helm/artifact-hub/artifact-hub core_maintainers: - https://github.com/tegioz - https://github.com/cynthia-sg - https://github.com/mattfarina dependencies_policy: https://github.com/artifacthub/hub/blob/master/CONTRIBUTING.md#dependencies-policy related_security_posture: clomonitor: >- The repository carries a .clomonitor.yml, so the project is tracked by the CNCF CLOMonitor open-source health checker. product_security_feature: >- Distinct from this policy: Artifact Hub itself SCANS the packages it lists using Trivy and publishes the reports (https://artifacthub.io/docs/topics/security_report/, operation getPackageSecurityReport). That is a product capability, not a disclosure program, and is recorded here only so the two are not confused.