mirror of
https://github.com/vmware-tanzu/velero.git
synced 2026-09-13 03:24:39 +00:00
Add a schema-valid OpenSSF Security Insights v2 (2.2.0) manifest at SECURITY-INSIGHTS.yml describing the project's maintainers, vulnerability reporting process, license, and links to governance, security, and dependency management policies. Also add a Dependency management section to the development docs covering Go modules, Dependabot automation, review process, and how security relevant dependency updates are handled. The manifest references this section as the dependency management policy. This improves the project's CLOMonitor score by satisfying the security_insights and dependencies_policy checks. Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>