generated: '2026-09-05' method: searched probe: true source: https://www.bestpractices.dev/projects/10564.json policy: - https://wiki.linuxfoundation.org/civilinfrastructureplatform/cipkernelmaintenance#security_fixes contact: - https://lists.cip-project.org/g/cip-dev tracker: - https://gitlab.com/cip-project/cip-kernel/cip-kernel-sec security_txt: false note: 'probe-security-programs.py found no security.txt and no disclosure page on cip-project.org (all 404). The disclosure process is nonetheless published: CIP''s own OpenSSF Best Practices submission records vulnerability_report_process_status: Met and vulnerability_response_process_status: Met, both citing the kernel-maintenance wiki page, with CVE tracking in the cip-kernel-sec repository. The wiki host answers our crawler with a Cloudflare bot challenge (403), so the page could not be read directly — the badge record is the evidence.' evidence: - source: https://www.bestpractices.dev/projects/10564.json kind: openssf-badge fields: - 'vulnerability_report_process_status: Met' - 'vulnerability_response_process_status: Met' - 'report_archive_status: Met' - 'vulnerabilities_fixed_60_days_status: Met' - source: https://gitlab.com/cip-project/cip-kernel/cip-kernel-sec kind: cve-tracker http_status: 200 - source: https://www.cip-project.org/.well-known/security.txt kind: security.txt http_status: 404