Skip to content

Commit

Permalink
Update security policy to outline current security scans (#3959)
Browse files Browse the repository at this point in the history
  • Loading branch information
axsaucedo authored Feb 21, 2022
1 parent 81c29fc commit 2499bea
Showing 1 changed file with 10 additions and 9 deletions.
19 changes: 10 additions & 9 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,19 +4,20 @@ This document provides an overview of the security policy of Seldon Core.

Seldon Core aims to follow the two following policies:

* Keep dependencies up to date
* Identify and address common vulnerabilities and exposures
* Address CVEs in project dependencies by upgrading versions where possible
* Address CVEs in docker images by performing recommended upgrades

## Supported Versions
# Security Scans

As part of every release we perform a security scan. The scans include dependencies and docker image scans.

The versions that support this Security policies are the following
You can find the [exact commands that are used](https://github.com/SeldonIO/seldon-core/blob/master/.github/workflows/security_tests.yml) for the scans, together with the [reports generated](https://github.com/SeldonIO/seldon-core/actions/workflows/security_tests.yml) from each of these runs.

## Supported Versions

| Version | Supported |
| ------- | ------------------ |
| >= 1.2.2 | :white_check_mark: |
| < 1.2.2 | :x: |
We use semver for our version management. We release security patches as a `patch version` for the latest maor.minor release.

## Reporting a Vulnerability

If you identify a vulnerability the best way to report it is by opening an issue with the type "bug". The discussion can then take place there on next steps (ie updating library, reaching out to 3rd party projects, etc).
If you identify a vulnerability, if a public CVE the best way to report it is by opening an issue with the type "bug", the discussion can then take place on the ticket around next steps (ie updating library, reaching out to 3rd party projects, etc).

0 comments on commit 2499bea

Please sign in to comment.