specification: API Commons Vulnerability Disclosure specificationVersion: '0.1' provider: Buoyant providerId: buoyant generated: '2026-09-04' method: searched source: https://github.com/linkerd/linkerd2/blob/main/SECURITY.md note: >- probe-security-programs.py reported vdp=none because Buoyant serves no /.well-known/security.txt and runs no HackerOne/Bugcrowd/Intigriti programme. It does, however, publish a written security policy with a named reporting channel, a criticality policy and published third-party audits — which is a real vulnerability disclosure programme. Recorded here as searched, on the evidence below. program: published: true policy_url: https://github.com/linkerd/linkerd2/blob/main/SECURITY.md reporting_channel: GitHub security advisory on the linkerd2 repository reporting_url: https://github.com/linkerd/linkerd2/security/advisories bug_bounty: false security_txt: false security_txt_note: >- /.well-known/security.txt returned 404 on buoyant.io, www.buoyant.io, linkerd.io, docs.buoyant.io and helm.buoyant.cloud (probed 2026-09-04). See well-known/buoyant-well-known.yml. triage_policy: >- "Critical issues that affect Linkerd's security posture or that reduce its ability to provide security for users will receive immediate attention and be fixed as quickly as possible." Non-affecting CVEs in underlying dependencies may not be addressed immediately. Security updates land in the next edge release once merged to main. practices: - Code review - Dependency hygiene and supply-chain security via Dependabot - Fuzz testing - Third-party security audits - Manual, static and dynamic checking audits: - name: Linkerd 2024 security audit (CNCF-funded, third party) published: true url: https://linkerd.io/2025/02/18/linkerd-2024-security-audit/ - name: Linkerd 2022 security audit published: true url: https://linkerd.io/2022/06/27/announcing-the-completion-of-linkerds-2022-security-audit/ - policy: SECURITY.md states audits are published unredacted. commercial_remediation: cve_sla: >- The Premium tier includes CVE remediation SLAs and the Strategic tier adds hotpatch releases and SBOMs, per https://www.buoyant.io/pricing. Numeric targets are contractual and not published. maintainers: - FN: Kin Lane email: kin@apievangelist.com