Add project processes guide

This guide defines more clearly how we prioritize issues,
releases, project scope, and security boundary.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
This commit is contained in:
Tonis Tiigi
2023-12-07 19:24:34 -08:00
parent bf84288d43
commit 3deb976a39
4 changed files with 184 additions and 3 deletions

3
.github/SECURITY.md vendored
View File

@@ -6,6 +6,9 @@ issue, please bring it to their attention right away!
**Please _DO NOT_ file a public issue**, instead send your report privately to
[security@docker.com](mailto:security@docker.com).
Explanation of BuildKit security boundary and what we consider a security issue can be found in [here](/PROJECT.md#security-boundary). If you are unsure if you have found a security issue, it is always better to check privately first.
Security reports are greatly appreciated, and we will publicly thank you for it
(if you want to). We also like to send gifts&mdash;if you're into schwag, make
sure to let us know. We currently do not offer a paid security bounty program,