kubernetes / committee-security-response

Kubernetes Security Process and Security Committee docs
Apache License 2.0
165 stars 65 forks source link

Document a policy for virus scanner false positive results on Kubernetes release artifacts #201

Open tabbysable opened 4 months ago

tabbysable commented 4 months ago

We occasionally get reports of malicious code detected in Kubernetes release artifacts that are ultimately due to virus-scanner false positives. It could be nice to have a policy for responding to these, to reduce the effort required.

k8s-triage-robot commented 1 month ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot commented 6 days ago

The Kubernetes project currently lacks enough active contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle rotten