Skip to content

docs: add SECURITY.md security policy#871

Merged
ArangoGutierrez merged 1 commit into
NVIDIA:mainfrom
ArangoGutierrez:feat/security-md
Jul 21, 2026
Merged

docs: add SECURITY.md security policy#871
ArangoGutierrez merged 1 commit into
NVIDIA:mainfrom
ArangoGutierrez:feat/security-md

Conversation

@ArangoGutierrez

Copy link
Copy Markdown
Collaborator

Adds a SECURITY.md security policy to holodeck (adapted from NVIDIA/k8s-test-infra).

Problem

Holodeck has no published security policy — vulnerability reporters have no documented private disclosure channel.

Approach

  • Supported versions: 0.3.x
  • Private reporting via GitHub Security Advisories + psirt@nvidia.com
  • Scope rewritten for holodeck's real AWS provisioning (VPC, EC2, security groups, IAM creds); SG ingress restricted to caller /32, never 0.0.0.0/0

Testing

Documentation only — rendered markdown reviewed; no code paths affected.

Breaking changes

None.

Holodeck had no published security policy, leaving vulnerability reporters
without a private disclosure channel. Add SECURITY.md adapted from the
NVIDIA/k8s-test-infra policy, with holodeck-specific adjustments: supported
version line (0.3.x), the NVIDIA/holodeck advisories URL, psirt@nvidia.com as
the reporting contact, and a Scope section rewritten to reflect that holodeck
provisions real ephemeral AWS infrastructure (VPCs, EC2, security groups,
IAM-scoped credentials) rather than mock infra.

Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
@ArangoGutierrez
ArangoGutierrez marked this pull request as ready for review July 21, 2026 08:25
@ArangoGutierrez
ArangoGutierrez merged commit 6f3ca80 into NVIDIA:main Jul 21, 2026
11 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant