Skip to content

add: security-insights.yml file #879

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
83 changes: 83 additions & 0 deletions .github/security-insights.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
header:
schema-version: 2.0.0
last-updated: "2025-04-03"
last-reviewed: "2025-04-03"
url: https://github.com/fluxcd/image-automation-controller/blob/main/.github/security-insights.yml
project-si-source: https://github.com/fluxcd/image-automation-controller/refs/heads/main/.github/security-insights.yml
comment: |
This file contains information about the image-automation-controller of the Flux project.

repository:
url: https://github.com/fluxcd/image-automation-controller
status: active
bug-fixes-only: false
accepts-change-request: true
accepts-automated-change-request: true
no-third-party-packages: false
core-team:
- name: Aurel Canciu
affiliation: NexHealth
email: aurel.canciu@nexhealth.com
social: "github: @relu, slack: relu"
primary: false
- name: Hidde Beydals
affiliation: Independent
email: hidde@hhh.computer
social: "github: @hiddeco, slack: hidde"
primary: false
- name: Matheus Pimenta
affiliation: ControlPlane
email: matheuscscp@linux.com
social: "github: @matheuscscp, slack: matheuscscp"
primary: false
- name: Max Jonas Werner
affiliation: Associmates
email: max.werner@associmates.eu
social: "github: @makkes, slack: max"
primary: false
- name: Paulo Gomes
affiliation: SUSE
email: pjbgf@linux.com
social: "github: @pjbgf, slack: pjbgf"
primary: false
- name: Sanskar Jaiswal
affiliation: Independent
email: jaiswalsanskar078@gmail.com
social: "github: @aryan9600, slack: aryan9600"
primary: false
- name: Soule BA
affiliation: ControlPlane
email: bah.soule@gmail.com
social: "github: @souleb, slack: souleb"
primary: false
- name: Stefan Prodan
affiliation: ControlPlane
email: stefan.prodan@gmail.com
social: "github: @stefanprodan, slack: stefanprodan"
primary: false
- name: Dipti Pai
affiliation: Microsoft
email: diptipai@microsoft.com
social: "github: @dipti-pai, slack: Dipti Pai"
primary: false
documentation:
contributing-guide: https://github.com/fluxcd/image-automation-controller/blob/main/DEVELOPMENT.md
security-policy: https://github.com/fluxcd/pkg/security
license:
url: https://github.com/fluxcd/image-automation-controller/blob/main/LICENSE
release:
changelog: https://github.com/fluxcd/image-automation-controller/blob/main/CHANGELOG.md
automated-pipeline: true
distribution-points:
- uri: https://github.com/fluxcd/image-automation-controller/releases
comment: Releases are following SemVer scheme.
license:
url: https://github.com/fluxcd/image-automation-controller/blob/main/LICENSE
expression: Apache-2.0
security:
assessments:
third-party:
- evidence: https://fluxcd.io/FluxFinalReport-v1.1.pdf
date: "2021-10-18"
comment: |
Overview available at https://fluxcd.io/blog/2021/11/flux-security-audit/