generated: '2026-09-12' method: searched source: >- https://github.com/Project-HAMi/HAMi/blob/master/SECURITY.md and https://github.com/Project-HAMi/HAMi/blob/master/SECURITY-INSIGHTS.yml (saved verbatim to security/hami-security-insights.yml) note: >- 0-working/probe-security-programs.py found nothing because HAMi serves no /.well-known/security.txt (404 on project-hami.io, www.project-hami.io and project-hami.github.io) and runs no bug bounty. The program is real, it is just published where an open-source project publishes it: a SECURITY.md in the repository root, machine-readably cross-declared in an OpenSSF Security Insights 2.0.0 document. Both were fetched for this record. program_published: true security_txt: false security_txt_note: >- Not served on any HAMi host. Adding one at https://project-hami.io/.well-known/security.txt pointing at SECURITY.md would make this program machine-discoverable; it is the single clearest gap in an otherwise well-published security posture. policy_url: https://github.com/Project-HAMi/HAMi/blob/master/SECURITY.md reporting: channel: GitHub Security Advisories (private vulnerability reporting) url: https://github.com/Project-HAMi/HAMi/security/advisories/new reports_accepted: true public_disclosure_before_process: discouraged contact_name: HAMi maintainers information_requested: - Clear and concise description of the vulnerability - Steps to reproduce - Potential attack scenarios or security impact - Suggested mitigations or fixes, if available bug_bounty: available: false evidence: >- SECURITY.md states "Currently, HAMi does not offer a public bug bounty program"; SECURITY-INSIGHTS.yml sets vulnerability-reporting.bug-bounty-available to false. response_target: detail: >- Maintainers aim to reply as soon as possible, ideally within 5 working days, allowing for weekends, holidays and time-zone differences. scope: in_scope: - A report that lets a workload reach another tenant's data, device, or namespace it was not granted. out_of_scope: - >- A report that a workload can exceed its own quota without affecting another tenant. HAMi states plainly that in-container enforcement (HAMi-core/libvgpu) limits GPU memory and compute for cooperative multi-tenant sharing on a TRUSTED cluster and "is not a hard security boundary against a workload with enough privilege to bypass its own hook, for example by unsetting LD_PRELOAD, using a static binary, or ptrace". That threat-model statement is unusually explicit and is the most useful single sentence in the policy for anyone evaluating HAMi as isolation. supported_versions: cross_ref: lifecycle/hami-lifecycle.yml security_tooling: source: security/hami-security-insights.yml tools: - {name: Dependabot, type: SCA, ci: true} - {name: CodeQL, type: SAST, ci: true} - {name: GitHub secret scanning, type: secret-scanning, ci: true, note: push protection enabled} additional: FOSSA license and dependency checks, and container image scanning, per the self-assessment comment. assessments: - name: CNCF general technical review url: https://github.com/Project-HAMi/HAMi/blob/master/docs/general-technical-review.md - name: Audit report (v2.9.0) url: https://github.com/Project-HAMi/HAMi/blob/master/docs/audit-report-v290.md trust_center: false certifications: []