generated: '2026-09-13' method: searched source: >- https://github.com/podman-container-tools/buildah/blob/main/SECURITY.md, https://github.com/containers/common/blob/main/SECURITY.md, https://github.com/podman-container-tools/buildah/security/policy name: Buildah vulnerability disclosure published: true policy_url: https://github.com/podman-container-tools/buildah/blob/main/SECURITY.md policy_inherits: https://github.com/containers/common/blob/main/SECURITY.md github_advisories: https://github.com/podman-container-tools/buildah/security/policy note: >- Buildah's SECURITY.md is a one-line pointer at the shared "Security and Disclosure Information Policy for the Containers Projects" maintained in containers/common. The substance below is quoted from that shared policy. reporting: channel: email contact: security@lists.podman.io private: true public_issue_prohibited: true instruction: >- "If you think you've identified a security issue in a Containers project, please DO NOT report the issue publicly via the Github issue tracker, mailing list, or IRC. Instead, send an email with as many details as possible to security@lists.podman.io. This is a private mailing list for the core maintainers." response_commitment: acknowledgement: within 3 working days quote: >- "Each report is acknowledged and analyzed by the core maintainers within 3 working days." ongoing: >- "As the security issue moves from triage, to an identified fix, to release planning, the core maintainers will keep the reporter updated." confidentiality: >- "Any vulnerability information shared with core maintainers stays within a Containers project and will not be disseminated to other projects unless it is necessary to get the issue fixed." announcements: channel: mailing list address: podman@lists.podman.io subscribe: https://lists.podman.io/admin/lists/podman.lists.podman.io/ note: >- "The podman@lists.podman.io email list is used for messages about Podman security announcements as well as general announcements and discussions." bug_bounty: exists: false platforms_checked: - HackerOne - Bugcrowd - Intigriti note: No bug bounty program found for Buildah or the Podman Container Tools project. security_txt: served: false probed: - url: https://buildah.io/.well-known/security.txt status: 404 - url: https://go.podman.io/.well-known/security.txt status: 404 note: >- No RFC 9116 security.txt is served on buildah.io. The disclosure policy is real and well-specified, but it is discoverable only through the repository — a machine reading the project's website cannot find it. The `SecurityTxt` pointer is NOT wired.