Commit Graph
4 Commits
Author SHA1 Message Date
Tiger Kaovilai 41b5e8b460 Align backport wording with Supported Versions policy
Run the E2E test on kind / get-go-version (push) Failing after 1m14s
Run the E2E test on kind / build (push) Has been skipped
Run the E2E test on kind / setup-test-matrix (push) Successful in 3s
Run the E2E test on kind / run-e2e-test (push) Has been skipped
CodeRabbit flagged step 8's "backport... into all earlier supported
releases" as contradicting the doc's own Supported Versions section
("Only the most recent version of Velero is supported"). Wording-only
fix, no policy change.

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
2026-07-22 14:12:04 -04:00
Tiger Kaovilai 0cf56826ac Update security contact email and links in SECURITY.md
Point contact email and mailing list at the CNCF Velero security
list (cncf-velero-security@lists.cncf.io) instead of the old
broadcom.com and dead googlegroups.com addresses. Fill in gaps
against CNCF's Security Guidelines for New Projects: add a Security
Contacts section, a Security Notification Template, and a link to
GitHub's private vulnerability reporting and the OpenSSF maintainer
guide. Drop the Velero Distributors embargo policy/mailing list
section since the project does not maintain one; default disclosure
practice is now to have a patched release ready at public disclosure
time. Fix the release-instructions.md link path (site/docs -> site/content/docs).

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
2026-07-22 13:09:12 -04:00
Xun Jiang/Bruce JiangandGitHub bfd9bc549d Replace security@vmware.com with velero-security.pdl@broadcom.com. (#8954)
Run the E2E test on kind / build (push) Failing after 7m0s
Run the E2E test on kind / setup-test-matrix (push) Successful in 2s
Run the E2E test on kind / run-e2e-test (push) Has been skipped
Main CI / Build (push) Failing after 32s
Close stale issues and PRs / stale (push) Successful in 11s
Trivy Nightly Scan / Trivy nightly scan (velero, main) (push) Failing after 4m53s
Trivy Nightly Scan / Trivy nightly scan (velero-plugin-for-aws, main) (push) Failing after 58s
Trivy Nightly Scan / Trivy nightly scan (velero-plugin-for-gcp, main) (push) Failing after 58s
Trivy Nightly Scan / Trivy nightly scan (velero-plugin-for-microsoft-azure, main) (push) Failing after 52s
Signed-off-by: Xun Jiang <xun.jiang@broadcom.com>
2025-05-22 09:47:05 -04:00
Jonas RoslandandGitHub 1dcaa1bf75 Rename security policy file to show up accurately in the GitHub UI (#2879)
Signed-off-by: jonasrosland <jrosland@vmware.com>
2020-08-31 12:10:09 -04:00