Skip to content

Proposal: Switch security reporting to GitHub private vulnerability reporting#291

Closed
Vad1mo wants to merge 1 commit into
goharbor:mainfrom
container-registry:github-private-vulnerability-reporting
Closed

Proposal: Switch security reporting to GitHub private vulnerability reporting#291
Vad1mo wants to merge 1 commit into
goharbor:mainfrom
container-registry:github-private-vulnerability-reporting

Conversation

@Vad1mo

@Vad1mo Vad1mo commented Jul 8, 2026

Copy link
Copy Markdown
Member

Proposal to replace the CNCF groups.io security mailing list (cncf-harbor-security@lists.cncf.io) with GitHub private vulnerability reporting and repository security advisories as Harbor's vulnerability intake and handling workflow.

Why

The mailing-list process is manual and fragmented: CVE requests are filed out-of-band with MITRE, fix PRs get developed in the public repo before embargo lifts, and email is a hurdle for reporters and maintainers.

Highlights

  • Every advantage in the proposal is backed by a GitHub Code Security doc reference
  • Intake, triage, embargoed fix (temporary private fork), CVE assignment (GitHub as CNA), and disclosure become one advisory artifact
  • Distributor coordination (cncf-harbor-distributors-announce) and disclosure timing are unchanged
  • CNCF does not mandate the list; Argo CD, in-toto, and Backstage already use GitHub's report form
  • Trade-offs and open issues are called out (GitHub account requirement, no CI on private forks, OCI/container Dependabot gap, spam triage)

Discussion: Harbor community meeting 8 July 2026

@Vad1mo
Vad1mo requested review from a team as code owners July 8, 2026 08:16
…ty reporting

Signed-off-by: Vadim Bauer <vb@container-registry.com>
@Vad1mo
Vad1mo force-pushed the github-private-vulnerability-reporting branch from dc36479 to 81787a4 Compare July 8, 2026 08:19
@Vad1mo Vad1mo closed this Jul 8, 2026
@Vad1mo
Vad1mo deleted the github-private-vulnerability-reporting branch July 8, 2026 08:28
@OrlinVasilev

Copy link
Copy Markdown
Member

@Vad1mo why did you close this one?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants