openyurtio / openyurt

OpenYurt - Extending your native Kubernetes to edge(project under CNCF)
https://openyurt.io
Apache License 2.0
1.68k stars 391 forks source link

a potential security risk #2018

Open HouqiyuA opened 3 months ago

HouqiyuA commented 3 months ago

We have recently discovered a potential security risk, and we would like to report it to you and provide relevant details so that you can take appropriate measures to address and improve it. We have already sent the specific details to your private email at openyurt@gmail.com.Looking forward to your reply!

rambohe-ch commented 2 months ago

@HouqiyuA Thanks for raising the issue. There are some problems about mail address: security@mail.openyurt.io, and the mail address for security disclosure is changed to: kubernetes-security@service.aliyun.com.

and this mail address upgrade will be fixed in this pull request: https://github.com/openyurtio/openyurt/pull/2026

would you like to transfer the mail to the address: kubernetes-security@service.aliyun.com ?

Thank you in advance.

From @rambohe-ch