| Version | Supported |
|---|---|
| 0.2.x | Supported |
| 0.1.x | Best effort |
If you discover a security vulnerability in agentic-operator, please report it responsibly. Do not open a public GitHub issue.
- Use GitHub private vulnerability reporting.
- Include steps to reproduce, affected versions, and potential impact.
- We aim to acknowledge receipt within 2 business days.
- Fix and disclosure timelines depend on severity, exploitability, and coordinated disclosure needs.
- A private acknowledgement through GitHub Security Advisories.
- Updates when triage status or disclosure timing changes.
- Credit in the release notes (unless you prefer anonymity).
The following are in scope:
- Kubernetes RBAC escalation via the operator
- Webhook bypass or admission validation flaws
- Secret leakage (credentials, tokens, keys)
- Container escape or privilege escalation
- Injection attacks via CRD fields
- Vulnerabilities in upstream dependencies (report to the upstream project)
- Denial-of-service via resource exhaustion (use ResourceQuota/LimitRange)
- Issues requiring physical access to the cluster nodes