logo
Dates

Author


Conferences

Tags

Sort by:  

Authors: Mo Khan, Micah Hausler
2023-04-20

tldr - powered by Generative AI

The presentation discusses the process of reporting and handling security issues in Kubernetes, including the role of the Security Committee and the Bug Bounty program.
  • The Security Committee assesses reported issues and works with code owners to determine if they are legitimate security issues.
  • CVEs are issued for security issues and the release team is involved if the issue affects core Kubernetes.
  • Distributors are notified for medium or high severity issues that may affect their users.
  • The Bug Bounty program offers rewards for responsibly reported security issues.
  • Reporting security issues through HackerOne or the email list is encouraged.