Project Security Contacts
Last updated: 2026-08-21
This page lists the security policy and vulnerability reporting channel for each
active CNCF project. The reporting channel is taken from each project's own
security policy (SECURITY.md), discovered through the project's
.project repository
metadata. It supports the CNCF's obligations as an open source steward under the
EU Cyber Resilience Act (CRA).
Of the 166 active projects with a .project repository: 124 publish a security
policy and 162 provide a vulnerability reporting channel.
To report a vulnerability in a CNCF project, use the project's vulnerability reporting link below. If a project has no reporting channel listed, contact security@cncf.io.
Entries marked ⚠️ Missing indicate the project has not yet published the
relevant security metadata. Maintainers can fix this by adding a SECURITY.md
to their project and referencing it from project.yaml in their .project
repository — see the
schema documentation.
Graduated
Incubating
Sandbox
Unknown maturity
| Project | Security policy | Report a vulnerability |
|---|---|---|
| cedar-policy | ⚠️ Missing | ⚠️ Missing |
| composefs | ⚠️ Missing | ⚠️ Missing |