security-policy

Create or update SECURITY.md files for CNCF projects with vulnerability reporting processes.

2|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/castrojo/cncf-skills --skill security-policy
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-policy
Source: https://github.com/castrojo/cncf-skills/tree/main/skills/security-policy
Command: npx skills add https://github.com/castrojo/cncf-skills --skill security-policy

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps CNCF projects establish or update their SECURITY.md file, ensuring clear guidelines for vulnerability reporting and disclosure.

Core Features & Use Cases

  • Security Policy Creation/Update: Generates or refines the SECURITY.md file.
  • Vulnerability Reporting: Defines the process for reporting security vulnerabilities.
  • Disclosure Timeline: Sets expectations for response and patch timelines.
  • Supported Versions: Documents which project versions are actively supported.
  • Use Case: A project needs to meet CNCF graduation requirements, which mandate a security policy. This Skill guides the creation of a compliant SECURITY.md file.

Quick Start

Use the security-policy skill to create or update the SECURITY.md file for this project.

Frequently Asked Questions about security-policy

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a SECURITY.md file for a CNCF project to meet graduation requirements?

To create a SECURITY.md file for a CNCF project, you need to define vulnerability reporting processes, disclosure timelines, and supported versions. This ensures compliance with security best practices and satisfies CNCF graduation mandates.

What should be included in a security policy for vulnerability reporting on GitHub?

A security policy for vulnerability reporting should include defined disclosure timelines, supported project versions, and integration with GitHub's Private Vulnerability Reporting. This sets clear expectations for response and patch timelines.

How does a security policy help in obtaining an OpenSSF badge?

A security policy helps obtain an OpenSSF badge by establishing a compliant SECURITY.md file and providing guidance on setting up OpenSSF tooling. This demonstrates adherence to recognized security best practices.

Can I use this to update an existing security policy or only to create a new one?

You can use this to both generate a new SECURITY.md file and refine an existing one. It updates vulnerability reporting processes and disclosure timelines to ensure ongoing compliance with current security standards.

What is the vulnerability disclosure process in a CNCF security policy?

The vulnerability disclosure process in a CNCF security policy defines how security issues are reported and sets expectations for response and patch timelines. It integrates with GitHub's Private Vulnerability Reporting for secure submissions.