openyurtio / openyurt

OpenYurt - Extending your native Kubernetes to edge(project under CNCF)
https://openyurt.io
Apache License 2.0
1.72k stars 405 forks source link

[Question] clarify email for reporting security vulnerabilities #2186

Open rochaporto opened 1 week ago

rochaporto commented 1 week ago

What happened:

Currently the SECURITY.md points to kubernetes-security@service.aliyun.com to report security vulnerabilities.

The documentation indicates all maintainers should be reached by these reports. Please clarify how this is the case, or update the target email appropriately if this was an oversight.

What you expected to happen:

The email relies on service.aliyun.com, i would expect it to reach an email behind openyurt.io.

How to reproduce it (as minimally and precisely as possible):

Anything else we need to know?:

Environment:

others /kind question