generated: '2026-09-12' method: searched source: https://github.com/goharbor/harbor/blob/main/SECURITY.md (fetched via raw.githubusercontent.com 2026-09-12) provider: Harbor providerId: goharbor description: >- Harbor publishes a full security release process: a private intake channel, an acknowledgement SLA, a CVSS-scored triage, an embargoed fix workflow, a distributors pre-announcement list and a public advisory step. The automated probe found nothing because there is no /.well-known/security.txt and no bug-bounty platform listing — the policy lives in the repository, where a CNCF project's policy normally does. policy_url: https://github.com/goharbor/harbor/blob/main/SECURITY.md security_txt: false bug_bounty: false intake: primary: channel: GitHub private vulnerability reporting url: https://github.com/goharbor/harbor/security/advisories/new note: Stated to be the ONLY channel for vulnerability reports; requires a GitHub account. team_contact: cncf-harbor-security@lists.cncf.io team_contact_note: For reaching the Harbor Security Team — explicitly NOT for filing vulnerability reports. public_issues_prohibited: true response: acknowledgement: within 5 business days severity_scoring: CVSS (https://www.first.org/cvss/specification-document), calculated in the draft advisory cve: Requested through the GitHub draft advisory where GitHub is the eligible CNA; otherwise coordinated with the covering CNA. fix_process: Patched in a temporary private fork under the advisory, embargoed, internally tested, then released. disclosure_target: Typically 14 business days from report to public disclosure for a critical vulnerability with a straightforward mitigation; the Security Team sets the final date. backports: Fixes backported to the three most recent minor release branches, severity and feasibility permitting. advisories: url: https://github.com/goharbor/harbor/security/advisories format: GitHub Security Advisories (GHSA), published with the CVE where GitHub issued it. early_disclosure: list: cncf-harbor-distributors-announce@lists.cncf.io audience: active Harbor distributors meeting published membership criteria embargo_policy: published in SECURITY.md supported_versions: policy: Release branches for the three most recent minor releases receive applicable security fixes. reference: https://github.com/goharbor/harbor/blob/main/RELEASES.md safe_harbor: published: false