Project Security Contacts
Last updated: 2026-09-11
This page lists the security policy and vulnerability reporting channel for each
active CNCF project. The reporting channel is taken from each project's own
security policy (SECURITY.md), discovered through the project's
.project repository
metadata. It supports the CNCF's obligations as an open source steward under the
EU Cyber Resilience Act (CRA).
Of the 220 active projects with a .project repository: 172 publish a security
policy and 215 provide a vulnerability reporting channel.
To report a vulnerability in a CNCF project, use the project's vulnerability
reporting link below. If a project has no reporting channel listed, contact
projects@cncf.io with a
subject line starting with [SECURITY].
Entries marked ⚠️ Missing indicate the project has not yet published the
relevant security metadata. Maintainers can fix this by adding a SECURITY.md
to their project and referencing it from project.yaml in their .project
repository — see the
schema documentation.
Graduated
Incubating
Sandbox
Unknown maturity
| Project | Security policy | Report a vulnerability |
|---|---|---|
| cedar-policy | ⚠️ Missing | ⚠️ Missing |
| composefs | ⚠️ Missing | ⚠️ Missing |
| sdcio | ⚠️ Missing | ⚠️ Missing |