Security: fluxcd/pkg

Security

SECURITY.md

Flux Security

This document defines security reporting, handling, disclosure, and audit information for the Flux project and community.

Also see our Flux Security documentation landing page for an overview of project security information geared toward end users.

Security Process

Report a Vulnerability

We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the Flux community.

  • To make a report please email the private security list at cncf-flux-security@lists.cncf.io with the details. We ask that reporters act in good faith by not disclosing the issue to others.
  • You may, but are not required to, encrypt your email to this list using the PGP keys of Security Team members, listed below.
  • The Security Team will fix the issue as soon as possible and coordinate a release date with you.
  • You will be able to choose if you want public acknowledgement of your effort and how you would like to be credited.

Security Team

Current Security Team members:

NameGitHubKey URLFingerprint
Hidde Beydals@hiddecohttps://keybase.io/hidde/pgp_keys.ascC910 7A9B 55A4 DD77 062B 9731 B6E3 6A6A C54A CD59
Matheus Pimenta@matheuscscphttps://keybase.io/matheuscscp/pgp_keys.ascB404 C733 A16F 589B 592A 4FD7 86D8 78C7 79EB 9A95
Stefan Prodan@stefanprodanhttps://keybase.io/stefanprodan/pgp_keys.asc613B F2C4 D985 BBCB 1474 123F 5A00 A045 0068 3EBD
Scott Rigby@scottrigbyhttps://keybase.io/r6by/pgp_keys.asc208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155

Handling

  • All reports are thoroughly investigated by the Security Team.
  • Any vulnerability information shared with the Security Team will not be shared with others unless it is necessary to fix the issue. Information is shared only on a need to know basis.
  • As the security issue moves through the identification and resolution process, the reporter will be notified.
  • Additional questions about the vulnerability may also be asked of the reporter.
  • Note that while Flux is very active it is a vendor-neutral CNCF project maintained by volunteers, not by a single company. As such, security issue handling is done on a best-effort basis. Talk to us if you are interested in getting involved with this work!

Disclosures

Vulnerability disclosures are emailed to the Flux Dev mailing list https://lists.cncf.io/g/cncf-flux-dev and announced publicly. Disclosures will contain an overview, details about the vulnerability, a fix that will typically be an update, and optionally a workaround if one is available.

We will coordinate publishing disclosures and security releases in a way that is realistic and necessary for end users. We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available. Disclosures will always be published in a timely manner after a release is published that fixes the vulnerability.

Advisories

The Flux security team publishes its advisories directly into the affected repositories. The main exception to this rule is flux2, which aggregates the CVEs across all Flux components (CLI and controllers).

The existing advisories can be found below:

Audits

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: fluxcd/pkg

Security

SECURITY.md

Flux Security

This document defines security reporting, handling, disclosure, and audit information for the Flux project and community.

Also see our Flux Security documentation landing page for an overview of project security information geared toward end users.

Security Process

Report a Vulnerability

We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the Flux community.

  • To make a report please email the private security list at cncf-flux-security@lists.cncf.io with the details. We ask that reporters act in good faith by not disclosing the issue to others.
  • You may, but are not required to, encrypt your email to this list using the PGP keys of Security Team members, listed below.
  • The Security Team will fix the issue as soon as possible and coordinate a release date with you.
  • You will be able to choose if you want public acknowledgement of your effort and how you would like to be credited.

Security Team

Current Security Team members:

NameGitHubKey URLFingerprint
Hidde Beydals@hiddecohttps://keybase.io/hidde/pgp_keys.ascC910 7A9B 55A4 DD77 062B 9731 B6E3 6A6A C54A CD59
Matheus Pimenta@matheuscscphttps://keybase.io/matheuscscp/pgp_keys.ascB404 C733 A16F 589B 592A 4FD7 86D8 78C7 79EB 9A95
Stefan Prodan@stefanprodanhttps://keybase.io/stefanprodan/pgp_keys.asc613B F2C4 D985 BBCB 1474 123F 5A00 A045 0068 3EBD
Scott Rigby@scottrigbyhttps://keybase.io/r6by/pgp_keys.asc208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155

Handling

  • All reports are thoroughly investigated by the Security Team.
  • Any vulnerability information shared with the Security Team will not be shared with others unless it is necessary to fix the issue. Information is shared only on a need to know basis.
  • As the security issue moves through the identification and resolution process, the reporter will be notified.
  • Additional questions about the vulnerability may also be asked of the reporter.
  • Note that while Flux is very active it is a vendor-neutral CNCF project maintained by volunteers, not by a single company. As such, security issue handling is done on a best-effort basis. Talk to us if you are interested in getting involved with this work!

Disclosures

Vulnerability disclosures are emailed to the Flux Dev mailing list https://lists.cncf.io/g/cncf-flux-dev and announced publicly. Disclosures will contain an overview, details about the vulnerability, a fix that will typically be an update, and optionally a workaround if one is available.

We will coordinate publishing disclosures and security releases in a way that is realistic and necessary for end users. We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available. Disclosures will always be published in a timely manner after a release is published that fixes the vulnerability.

Advisories

The Flux security team publishes its advisories directly into the affected repositories. The main exception to this rule is flux2, which aggregates the CVEs across all Flux components (CLI and controllers).

The existing advisories can be found below:

Audits

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: fluxcd/pkg

Security

SECURITY.md

Flux Security

This document defines security reporting, handling, disclosure, and audit information for the Flux project and community.

Also see our Flux Security documentation landing page for an overview of project security information geared toward end users.

Security Process

Report a Vulnerability

We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the Flux community.

  • To make a report please email the private security list at cncf-flux-security@lists.cncf.io with the details. We ask that reporters act in good faith by not disclosing the issue to others.
  • You may, but are not required to, encrypt your email to this list using the PGP keys of Security Team members, listed below.
  • The Security Team will fix the issue as soon as possible and coordinate a release date with you.
  • You will be able to choose if you want public acknowledgement of your effort and how you would like to be credited.

Security Team

Current Security Team members:

NameGitHubKey URLFingerprint
Hidde Beydals@hiddecohttps://keybase.io/hidde/pgp_keys.ascC910 7A9B 55A4 DD77 062B 9731 B6E3 6A6A C54A CD59
Matheus Pimenta@matheuscscphttps://keybase.io/matheuscscp/pgp_keys.ascB404 C733 A16F 589B 592A 4FD7 86D8 78C7 79EB 9A95
Stefan Prodan@stefanprodanhttps://keybase.io/stefanprodan/pgp_keys.asc613B F2C4 D985 BBCB 1474 123F 5A00 A045 0068 3EBD
Scott Rigby@scottrigbyhttps://keybase.io/r6by/pgp_keys.asc208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155

Handling

  • All reports are thoroughly investigated by the Security Team.
  • Any vulnerability information shared with the Security Team will not be shared with others unless it is necessary to fix the issue. Information is shared only on a need to know basis.
  • As the security issue moves through the identification and resolution process, the reporter will be notified.
  • Additional questions about the vulnerability may also be asked of the reporter.
  • Note that while Flux is very active it is a vendor-neutral CNCF project maintained by volunteers, not by a single company. As such, security issue handling is done on a best-effort basis. Talk to us if you are interested in getting involved with this work!

Disclosures

Vulnerability disclosures are emailed to the Flux Dev mailing list https://lists.cncf.io/g/cncf-flux-dev and announced publicly. Disclosures will contain an overview, details about the vulnerability, a fix that will typically be an update, and optionally a workaround if one is available.

We will coordinate publishing disclosures and security releases in a way that is realistic and necessary for end users. We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available. Disclosures will always be published in a timely manner after a release is published that fixes the vulnerability.

Advisories

The Flux security team publishes its advisories directly into the affected repositories. The main exception to this rule is flux2, which aggregates the CVEs across all Flux components (CLI and controllers).

The existing advisories can be found below:

Audits

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: fluxcd/pkg

Security

SECURITY.md

Flux Security

This document defines security reporting, handling, disclosure, and audit information for the Flux project and community.

Also see our Flux Security documentation landing page for an overview of project security information geared toward end users.

Security Process

Report a Vulnerability

We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the Flux community.

  • To make a report please email the private security list at cncf-flux-security@lists.cncf.io with the details. We ask that reporters act in good faith by not disclosing the issue to others.
  • You may, but are not required to, encrypt your email to this list using the PGP keys of Security Team members, listed below.
  • The Security Team will fix the issue as soon as possible and coordinate a release date with you.
  • You will be able to choose if you want public acknowledgement of your effort and how you would like to be credited.

Security Team

Current Security Team members:

NameGitHubKey URLFingerprint
Hidde Beydals@hiddecohttps://keybase.io/hidde/pgp_keys.ascC910 7A9B 55A4 DD77 062B 9731 B6E3 6A6A C54A CD59
Matheus Pimenta@matheuscscphttps://keybase.io/matheuscscp/pgp_keys.ascB404 C733 A16F 589B 592A 4FD7 86D8 78C7 79EB 9A95
Stefan Prodan@stefanprodanhttps://keybase.io/stefanprodan/pgp_keys.asc613B F2C4 D985 BBCB 1474 123F 5A00 A045 0068 3EBD
Scott Rigby@scottrigbyhttps://keybase.io/r6by/pgp_keys.asc208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155

Handling

  • All reports are thoroughly investigated by the Security Team.
  • Any vulnerability information shared with the Security Team will not be shared with others unless it is necessary to fix the issue. Information is shared only on a need to know basis.
  • As the security issue moves through the identification and resolution process, the reporter will be notified.
  • Additional questions about the vulnerability may also be asked of the reporter.
  • Note that while Flux is very active it is a vendor-neutral CNCF project maintained by volunteers, not by a single company. As such, security issue handling is done on a best-effort basis. Talk to us if you are interested in getting involved with this work!

Disclosures

Vulnerability disclosures are emailed to the Flux Dev mailing list https://lists.cncf.io/g/cncf-flux-dev and announced publicly. Disclosures will contain an overview, details about the vulnerability, a fix that will typically be an update, and optionally a workaround if one is available.

We will coordinate publishing disclosures and security releases in a way that is realistic and necessary for end users. We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available. Disclosures will always be published in a timely manner after a release is published that fixes the vulnerability.

Advisories

The Flux security team publishes its advisories directly into the affected repositories. The main exception to this rule is flux2, which aggregates the CVEs across all Flux components (CLI and controllers).

The existing advisories can be found below:

Audits

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: fluxcd/pkg

Security

SECURITY.md

Flux Security

This document defines security reporting, handling, disclosure, and audit information for the Flux project and community.

Also see our Flux Security documentation landing page for an overview of project security information geared toward end users.

Security Process

Report a Vulnerability

We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the Flux community.

  • To make a report please email the private security list at cncf-flux-security@lists.cncf.io with the details. We ask that reporters act in good faith by not disclosing the issue to others.
  • You may, but are not required to, encrypt your email to this list using the PGP keys of Security Team members, listed below.
  • The Security Team will fix the issue as soon as possible and coordinate a release date with you.
  • You will be able to choose if you want public acknowledgement of your effort and how you would like to be credited.

Security Team

Current Security Team members:

NameGitHubKey URLFingerprint
Hidde Beydals@hiddecohttps://keybase.io/hidde/pgp_keys.ascC910 7A9B 55A4 DD77 062B 9731 B6E3 6A6A C54A CD59
Matheus Pimenta@matheuscscphttps://keybase.io/matheuscscp/pgp_keys.ascB404 C733 A16F 589B 592A 4FD7 86D8 78C7 79EB 9A95
Stefan Prodan@stefanprodanhttps://keybase.io/stefanprodan/pgp_keys.asc613B F2C4 D985 BBCB 1474 123F 5A00 A045 0068 3EBD
Scott Rigby@scottrigbyhttps://keybase.io/r6by/pgp_keys.asc208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155

Handling

  • All reports are thoroughly investigated by the Security Team.
  • Any vulnerability information shared with the Security Team will not be shared with others unless it is necessary to fix the issue. Information is shared only on a need to know basis.
  • As the security issue moves through the identification and resolution process, the reporter will be notified.
  • Additional questions about the vulnerability may also be asked of the reporter.
  • Note that while Flux is very active it is a vendor-neutral CNCF project maintained by volunteers, not by a single company. As such, security issue handling is done on a best-effort basis. Talk to us if you are interested in getting involved with this work!

Disclosures

Vulnerability disclosures are emailed to the Flux Dev mailing list https://lists.cncf.io/g/cncf-flux-dev and announced publicly. Disclosures will contain an overview, details about the vulnerability, a fix that will typically be an update, and optionally a workaround if one is available.

We will coordinate publishing disclosures and security releases in a way that is realistic and necessary for end users. We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available. Disclosures will always be published in a timely manner after a release is published that fixes the vulnerability.

Advisories

The Flux security team publishes its advisories directly into the affected repositories. The main exception to this rule is flux2, which aggregates the CVEs across all Flux components (CLI and controllers).

The existing advisories can be found below:

Audits

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: fluxcd/pkg

Security

SECURITY.md

Flux Security

This document defines security reporting, handling, disclosure, and audit information for the Flux project and community.

Also see our Flux Security documentation landing page for an overview of project security information geared toward end users.

Security Process

Report a Vulnerability

We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the Flux community.

  • To make a report please email the private security list at cncf-flux-security@lists.cncf.io with the details. We ask that reporters act in good faith by not disclosing the issue to others.
  • You may, but are not required to, encrypt your email to this list using the PGP keys of Security Team members, listed below.
  • The Security Team will fix the issue as soon as possible and coordinate a release date with you.
  • You will be able to choose if you want public acknowledgement of your effort and how you would like to be credited.

Security Team

Current Security Team members:

NameGitHubKey URLFingerprint
Hidde Beydals@hiddecohttps://keybase.io/hidde/pgp_keys.ascC910 7A9B 55A4 DD77 062B 9731 B6E3 6A6A C54A CD59
Matheus Pimenta@matheuscscphttps://keybase.io/matheuscscp/pgp_keys.ascB404 C733 A16F 589B 592A 4FD7 86D8 78C7 79EB 9A95
Stefan Prodan@stefanprodanhttps://keybase.io/stefanprodan/pgp_keys.asc613B F2C4 D985 BBCB 1474 123F 5A00 A045 0068 3EBD
Scott Rigby@scottrigbyhttps://keybase.io/r6by/pgp_keys.asc208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155

Handling

  • All reports are thoroughly investigated by the Security Team.
  • Any vulnerability information shared with the Security Team will not be shared with others unless it is necessary to fix the issue. Information is shared only on a need to know basis.
  • As the security issue moves through the identification and resolution process, the reporter will be notified.
  • Additional questions about the vulnerability may also be asked of the reporter.
  • Note that while Flux is very active it is a vendor-neutral CNCF project maintained by volunteers, not by a single company. As such, security issue handling is done on a best-effort basis. Talk to us if you are interested in getting involved with this work!

Disclosures

Vulnerability disclosures are emailed to the Flux Dev mailing list https://lists.cncf.io/g/cncf-flux-dev and announced publicly. Disclosures will contain an overview, details about the vulnerability, a fix that will typically be an update, and optionally a workaround if one is available.

We will coordinate publishing disclosures and security releases in a way that is realistic and necessary for end users. We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available. Disclosures will always be published in a timely manner after a release is published that fixes the vulnerability.

Advisories

The Flux security team publishes its advisories directly into the affected repositories. The main exception to this rule is flux2, which aggregates the CVEs across all Flux components (CLI and controllers).

The existing advisories can be found below:

Audits

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: fluxcd/pkg

Security

SECURITY.md

Flux Security

This document defines security reporting, handling, disclosure, and audit information for the Flux project and community.

Also see our Flux Security documentation landing page for an overview of project security information geared toward end users.

Security Process

Report a Vulnerability

We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the Flux community.

  • To make a report please email the private security list at cncf-flux-security@lists.cncf.io with the details. We ask that reporters act in good faith by not disclosing the issue to others.
  • You may, but are not required to, encrypt your email to this list using the PGP keys of Security Team members, listed below.
  • The Security Team will fix the issue as soon as possible and coordinate a release date with you.
  • You will be able to choose if you want public acknowledgement of your effort and how you would like to be credited.

Security Team

Current Security Team members:

NameGitHubKey URLFingerprint
Hidde Beydals@hiddecohttps://keybase.io/hidde/pgp_keys.ascC910 7A9B 55A4 DD77 062B 9731 B6E3 6A6A C54A CD59
Matheus Pimenta@matheuscscphttps://keybase.io/matheuscscp/pgp_keys.ascB404 C733 A16F 589B 592A 4FD7 86D8 78C7 79EB 9A95
Stefan Prodan@stefanprodanhttps://keybase.io/stefanprodan/pgp_keys.asc613B F2C4 D985 BBCB 1474 123F 5A00 A045 0068 3EBD
Scott Rigby@scottrigbyhttps://keybase.io/r6by/pgp_keys.asc208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155

Handling

  • All reports are thoroughly investigated by the Security Team.
  • Any vulnerability information shared with the Security Team will not be shared with others unless it is necessary to fix the issue. Information is shared only on a need to know basis.
  • As the security issue moves through the identification and resolution process, the reporter will be notified.
  • Additional questions about the vulnerability may also be asked of the reporter.
  • Note that while Flux is very active it is a vendor-neutral CNCF project maintained by volunteers, not by a single company. As such, security issue handling is done on a best-effort basis. Talk to us if you are interested in getting involved with this work!

Disclosures

Vulnerability disclosures are emailed to the Flux Dev mailing list https://lists.cncf.io/g/cncf-flux-dev and announced publicly. Disclosures will contain an overview, details about the vulnerability, a fix that will typically be an update, and optionally a workaround if one is available.

We will coordinate publishing disclosures and security releases in a way that is realistic and necessary for end users. We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available. Disclosures will always be published in a timely manner after a release is published that fixes the vulnerability.

Advisories

The Flux security team publishes its advisories directly into the affected repositories. The main exception to this rule is flux2, which aggregates the CVEs across all Flux components (CLI and controllers).

The existing advisories can be found below:

Audits

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: fluxcd/pkg

Security

SECURITY.md

Flux Security

This document defines security reporting, handling, disclosure, and audit information for the Flux project and community.

Also see our Flux Security documentation landing page for an overview of project security information geared toward end users.

Security Process

Report a Vulnerability

We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the Flux community.

  • To make a report please email the private security list at cncf-flux-security@lists.cncf.io with the details. We ask that reporters act in good faith by not disclosing the issue to others.
  • You may, but are not required to, encrypt your email to this list using the PGP keys of Security Team members, listed below.
  • The Security Team will fix the issue as soon as possible and coordinate a release date with you.
  • You will be able to choose if you want public acknowledgement of your effort and how you would like to be credited.

Security Team

Current Security Team members:

NameGitHubKey URLFingerprint
Hidde Beydals@hiddecohttps://keybase.io/hidde/pgp_keys.ascC910 7A9B 55A4 DD77 062B 9731 B6E3 6A6A C54A CD59
Matheus Pimenta@matheuscscphttps://keybase.io/matheuscscp/pgp_keys.ascB404 C733 A16F 589B 592A 4FD7 86D8 78C7 79EB 9A95
Stefan Prodan@stefanprodanhttps://keybase.io/stefanprodan/pgp_keys.asc613B F2C4 D985 BBCB 1474 123F 5A00 A045 0068 3EBD
Scott Rigby@scottrigbyhttps://keybase.io/r6by/pgp_keys.asc208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155

Handling

  • All reports are thoroughly investigated by the Security Team.
  • Any vulnerability information shared with the Security Team will not be shared with others unless it is necessary to fix the issue. Information is shared only on a need to know basis.
  • As the security issue moves through the identification and resolution process, the reporter will be notified.
  • Additional questions about the vulnerability may also be asked of the reporter.
  • Note that while Flux is very active it is a vendor-neutral CNCF project maintained by volunteers, not by a single company. As such, security issue handling is done on a best-effort basis. Talk to us if you are interested in getting involved with this work!

Disclosures

Vulnerability disclosures are emailed to the Flux Dev mailing list https://lists.cncf.io/g/cncf-flux-dev and announced publicly. Disclosures will contain an overview, details about the vulnerability, a fix that will typically be an update, and optionally a workaround if one is available.

We will coordinate publishing disclosures and security releases in a way that is realistic and necessary for end users. We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available. Disclosures will always be published in a timely manner after a release is published that fixes the vulnerability.

Advisories

The Flux security team publishes its advisories directly into the affected repositories. The main exception to this rule is flux2, which aggregates the CVEs across all Flux components (CLI and controllers).

The existing advisories can be found below:

Audits

There aren't any published security advisories