generated: '2026-09-05' method: searched source: https://github.com/buildpacks/.github/blob/main/SECURITY.md provider: Cloud Native Buildpacks providerId: buildpacks published: true policy_url: https://github.com/buildpacks/.github/blob/main/SECURITY.md description: >- Cloud Native Buildpacks publishes a full coordinated-disclosure policy — reporting channels, a PGP key, an acknowledgment SLA, a defined response process and a public disclosure venue. It is NOT served at /.well-known/security.txt (that path 404s on every host, see well-known/buildpacks-well-known.yml); it lives in the organization-wide .github repository, which is where GitHub surfaces it on every buildpacks/* repo's Security tab. reporting: channels: - type: github-security-advisory url: https://github.com/buildpacks/community/security/advisories/new - type: email address: security@buildpacks.io pgp_fingerprint: 7AA4 452E A0C3 56F8 894D C869 4E56 F857 5412 6F64 pgp_keyserver: pgp.mit.edu scope_note: >- "These channels should only be used for reporting undisclosed security vulnerabilities in Cloud Native Buildpacks products." Regular bug reports are explicitly out of scope. requested_content: - affected software and versions - steps to reproduce - impact / potential consequences - suggested severity - logs, screenshots or proof-of-concept code response_process: acknowledgment_sla: 72 hours steps: - Acknowledgment within 72 hours by the security team. - Triage — a maintainer is assigned to investigate and validate, contacting the reporter directly if more is needed. - Advisory draft — a draft GitHub Security Advisory is created to coordinate with reporter and maintainers. - Fix development in private; patch and disclosure dates agreed with the reporter. - Disclosure once the fix ships, via GitHub Security Advisories and project release notes. coordinated_disclosure: true embargo: negotiated with the reporter rather than fixed public_disclosure: venues: - https://github.com/buildpacks/community/security/advisories - project release notes supported_versions: policy: >- "Security fixes are applied to the latest release of each Cloud Native Buildpacks project. Users are encouraged to stay on the most recent release to receive security updates." backports: false bug_bounty: offered: false note: >- No HackerOne, Bugcrowd or Intigriti program was found. probe-security-programs.py reported vdp=none trust=none on 2026-09-05 because it looks for a security.txt / bounty page rather than an org .github SECURITY.md — the policy is real, the automated probe simply misses this shape. audits: - type: third-party security audit date: '2024-07-17' auditor: Quarkslab, funded by the CNCF and coordinated by OSTIF report: https://ostif.org/buildpacks-audit-complete/ - type: CNCF security self-assessment date: '2021-09-07' note: Filed in the cncf/toc repository as part of the incubation process. badges: - name: OpenSSF (CII) Best Practices url: https://bestpractices.coreinfrastructure.org/projects/4748