generated: '2026-09-17' method: searched source: https://github.com/buildpacks/.github/blob/main/SECURITY.md published: true policy_url: https://github.com/buildpacks/.github/blob/main/SECURITY.md note: >- The project publishes a full coordinated-disclosure policy, but not at /.well-known/security.txt — every host in this record 404s that path (see well-known/). The policy is a repository SECURITY.md in the buildpacks/.github org-default repository, which GitHub surfaces on the Security tab of every buildpacks repo. contacts: - type: email value: security@buildpacks.io - type: github-security-advisory value: https://github.com/buildpacks/community/security/advisories/new pgp: fingerprint: 7AA4 452E A0C3 56F8 894D C869 4E56 F857 5412 6F64 keyserver: pgp.mit.edu process: acknowledgement: within 72 hours triage: a maintainer is assigned to investigate and validate coordination: draft GitHub Security Advisory shared with the reporter fix: developed privately; patch and disclosure date agreed with the reporter disclosure: published as a GitHub Security Advisory plus project release notes supported_versions: latest release of each Cloud Native Buildpacks project bug_bounty: offered: false note: No HackerOne, Bugcrowd or Intigriti program; disclosure is unpaid and coordinated. advisories: https://github.com/buildpacks/community/security/advisories audits: - type: third-party security audit date: '2024-07-17' funder: CNCF auditor: OSTIF report: https://ostif.org/buildpacks-audit-complete/ - type: CNCF self-assessment date: '2021-09-07' report: https://github.com/hone/toc/blob/master/projects/buildpacks/security-assessment/self-assessment.md evidence: - url: https://github.com/buildpacks/.github/blob/main/SECURITY.md status: 200 - url: https://buildpacks.io/.well-known/security.txt status: 404