generated: '2026-09-05' method: searched probe: true source: https://carvel.dev/shared/docs/latest/security-policy/ note: >- probe-security-programs.py returned vdp=none because it checks /security, /responsible-disclosure and /.well-known/security.txt, all of which 404 on carvel.dev. The policy is real; it lives one level down, under the shared docs tree, and it is a full CNCF-style coordinated-disclosure process rather than a contact line. policy: - https://carvel.dev/shared/docs/latest/security-policy/ - https://github.com/carvel-dev/ytt/blob/develop/SECURITY.md contact: - cncf-carvel-maintainers@lists.cncf.io security_txt: false security_txt_note: /.well-known/security.txt returned 404 on carvel.dev (2026-09-05). bug_bounty: false process: private_reporting: true github_issues_discouraged: true coordinator_assigned: true embargo: true disclosure: >- A public disclosure date is negotiated between the Carvel maintainers, the reporter and the distributors list; the project's stated preference is full disclosure as soon as a mitigation or patch is available. report_template_published: true risk_taxonomy_published: true scope_triggers: - A confirmed vulnerability in Carvel - A published CVE Carvel may be exposed to - A suspected security flaw with no confirmed attack vector - A vulnerability in one of Carvel's dependencies evidence: - {source: 'https://carvel.dev/shared/docs/latest/security-policy/', http_status: 200, kind: security-policy-page} - {source: 'https://raw.githubusercontent.com/carvel-dev/ytt/develop/SECURITY.md', http_status: 200, kind: repo-security-md} - {source: 'https://carvel.dev/.well-known/security.txt', http_status: 404, kind: security-txt-absent}