Tim Bannister
Tim Bannister
We should publish this once we're ready to. /approve ### :stop_sign: Do not merge or unhold until Kubernetes v1.31 is released :stop_sign:
@neoaggelos this post is definite **not** yet ready to publish (it's missing key details), so: /lgtm cancel
This is about https://kubernetes.io/docs/reference/issues-security/official-cve-feed/ and the feeds it links to. /sig security
The CVE feed lists vulnerabilities in Kubernetes' core. I don't think we make that as clear as we could.
/retitle CVE feed doesn't include some vulnerabilities for in-project code
The people working on the KEP could take steps to ensure the upstream feed includes more data; you can't fix this purely by committing to k/website. However, there's more than...
In the meantime, we could clarify in the web page about what's in scope.
OK, sounds good. /close
@SayakMukhopadhyay an aside: if you'd be willing to work on part of the equivalent change for https://k8s.io/, I can make time to pair up with you on that. I'm `@sftim`...