# Security ## Reporting a Vulnerability If you find a security related bug in Argo Workflows, we kindly ask you for responsible disclosure and for giving us appropriate time to react, analyze and develop a fix to mitigate the found security vulnerability. Please report vulnerabilities by opening a draft GitHub Security Advisory: https://github.com/argoproj/argo-workflows/security/advisories/new All vulnerabilities and associated information will be treated with full confidentiality. ## Public Disclosure Security vulnerabilities will be disclosed via [release notes](CHANGELOG.md) and using the [GitHub Security Advisories](https://github.com/argoproj/argo-workflows/security/advisories) feature to keep our community well informed, and will credit you for your findings (unless you prefer to stay anonymous, of course). ## Vulnerability Scanning See [static code analysis](docs/static-code-analysis.md). ## Securing Argo Workflows See [docs/security.md](docs/security.md) for information about securing your Argo Workflows instance.