Skip to content

Commit 4e8e6fe

Browse files
Vinaya DamleDariuszPorowski
andcommitted
Add security-insights.yml for OSSF Security Insights v2.0.0
Co-authored-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com> Signed-off-by: vinayada1 <28875764+vinayada1@users.noreply.github.com>
1 parent 0a26e31 commit 4e8e6fe

2 files changed

Lines changed: 192 additions & 1 deletion

File tree

.github/security-insights.yml

Lines changed: 191 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,191 @@
1+
header:
2+
schema-version: 2.0.0
3+
last-updated: '2026-02-20'
4+
last-reviewed: '2026-02-20'
5+
url: https://github.com/radius-project/radius
6+
comment: >-
7+
This file contains all possible information for both project and repository,
8+
though it is not required to include all of this information every time. Nor
9+
is it required to include both a project and repository section if the
10+
project section is intended to be inherited by repositories via
11+
header.project-si-source
12+
project:
13+
name: Radius
14+
homepage: https://radapp.io
15+
roadmap: https://aka.ms/radius-roadmap
16+
steward:
17+
uri: ''
18+
comment: No steward designated
19+
administrators:
20+
- name: Sylvain Niles
21+
affiliation: Microsoft
22+
social: https://github.com/sylvainsf
23+
primary: false
24+
- name: Karishma Chawla
25+
affiliation: Microsoft
26+
social: https://github.com/kachawla
27+
primary: false
28+
- name: Brooke Hamilton
29+
affiliation: Microsoft
30+
social: https://github.com/brooke-hamilton
31+
primary: false
32+
documentation:
33+
quickstart-guide: https://docs.radapp.io/quick-start/
34+
detailed-guide: https://radapp.io/
35+
code-of-conduct: https://github.com/radius-project/community/blob/main/CODE-OF-CONDUCT.md
36+
release-process: https://github.com/radius-project/community
37+
support-policy: https://github.com/radius-project/radius/blob/main/SUPPORT.md
38+
repositories:
39+
- name: Radius
40+
url: https://github.com/radius-project/radius
41+
comment: >-
42+
Radius is the main Radius repository. It contains all of Radius code and
43+
documentation. In addition, we have the below repositories
44+
- name: Docs
45+
url: https://github.com/radius-project/docs
46+
comment: This repository contains the Radius documentation source for Radius.
47+
- name: Samples
48+
url: https://github.com/radius-project/samples
49+
comment: >-
50+
This repository contains the source code for quickstarts, reference
51+
apps, and tutorials for Radius.
52+
- name: Recipes
53+
url: https://github.com/radius-project/recipes
54+
comment: >-
55+
This repo contains commonly used Recipe templates for Radius
56+
Environments.
57+
- name: Website
58+
url: https://github.com/radius-project/website
59+
comment: This repository contains the source code for the Radius website.
60+
- name: AWS Bicep Types
61+
url: https://github.com/radius-project/bicep-types-aws
62+
comment: >-
63+
This repository contains the tooling for Bicep support for AWS resource
64+
types.
65+
- name: Radius Resource Types and Recipes Contributions
66+
url: https://github.com/radius-project/resource-types-contrib
67+
comment: >-
68+
This repository contains the Resource Type definitions and Recipes for deploying those Resource Types via Radius.
69+
vulnerability-reporting:
70+
reports-accepted: true
71+
bug-bounty-available: false
72+
contact:
73+
name: Radius Team
74+
email: radiuscoreteam@service.microsoft.com
75+
primary: true
76+
policy: https://github.com/radius-project/radius/blob/main/SECURITY.md
77+
repository:
78+
url: https://github.com/radius-project/radius
79+
status: active
80+
bug-fixes-only: true
81+
accepts-change-request: true
82+
accepts-automated-change-request: true
83+
no-third-party-packages: true
84+
license:
85+
url: >-
86+
https://github.com/radius-project/radius/blob/main/LICENSE
87+
expression: Apache-2.0
88+
core-team:
89+
- name: Radius Core Team
90+
affiliation: Microsoft
91+
email: radiuscoreteam@service.microsoft.com
92+
primary: true
93+
- name: Sylvain Niles
94+
affiliation: Microsoft
95+
social: https://github.com/sylvainsf
96+
primary: false
97+
- name: Karishma Chawla
98+
affiliation: Microsoft
99+
social: https://github.com/kachawla
100+
primary: false
101+
- name: Brooke Hamilton
102+
affiliation: Microsoft
103+
social: https://github.com/brooke-hamilton
104+
primary: false
105+
documentation:
106+
contributing-guide: https://github.com/radius-project/radius/blob/main/CONTRIBUTING.md
107+
review-policy: >-
108+
https://github.com/radius-project/radius/blob/main/docs/contributing/contributing-code/contributing-code-reviewing/README.md
109+
security-policy: https://github.com/radius-project/radius/blob/main/SECURITY.md
110+
governance: >-
111+
https://github.com/radius-project/community/blob/main/community-membership.md
112+
dependency-management-policy: https://github.com/radius-project/radius/blob/main/THIRD-PARTY-NOTICES.txt
113+
release:
114+
changelog: https://github.com/radius-project/radius/releases
115+
automated-pipeline: false
116+
attestations:
117+
- name: Release 0.54
118+
predicate-uri: https://github.com/radius-project/radius/actions/runs/20080596572
119+
location: https://github.com/radius-project/radius/releases/tag/v0.54.0
120+
comment: Build workflow for Release 0.54
121+
distribution-points:
122+
- uri: https://github.com/radius-project/radius/releases
123+
comment: Radius Releases
124+
- uri: https://github.com/orgs/radius-project/packages?repo_name=radius
125+
comment: GitHub packages
126+
license:
127+
url: >-
128+
https://github.com/radius-project/radius/blob/main/LICENSE
129+
expression: Apache-2.0
130+
security:
131+
assessments:
132+
self:
133+
evidence: https://github.com/radius-project/design-notes/tree/main/architecture
134+
comment: >-
135+
https://github.com/radius-project/design-notes/blob/main/architecture/2024-08-controller-component-threat-model.md
136+
137+
https://github.com/radius-project/design-notes/blob/main/architecture/2024-08-applications-rp-component-threat-model.md
138+
139+
https://github.com/radius-project/design-notes/blob/main/architecture/2024-08-dashboard-component-threat-model.md
140+
141+
https://github.com/radius-project/design-notes/blob/main/architecture/2024-11-ucp-component-threat-model.md
142+
third-party:
143+
- comment: No third-party assessment performed
144+
champions:
145+
- name: Radius Team
146+
email: radiuscoreteam@service.microsoft.com
147+
primary: true
148+
tools:
149+
- name: Scorecard
150+
type: SCA
151+
rulesets:
152+
- default
153+
results: {}
154+
integration:
155+
adhoc: false
156+
ci: true
157+
release: false
158+
- name: CodeQL
159+
type: SAST
160+
version: '2'
161+
rulesets:
162+
- default
163+
results:
164+
ci:
165+
name: CodeQL GitHub workflow
166+
predicate-uri: ''
167+
location: >-
168+
https://github.com/radius-project/radius/blob/main/.github/workflows/codeql.yml
169+
comment: GitHub workflow to run CodeQL
170+
integration:
171+
adhoc: false
172+
ci: true
173+
release: false
174+
- name: GoSec
175+
type: SAST
176+
rulesets:
177+
- default
178+
results: {}
179+
integration:
180+
adhoc: false
181+
ci: true
182+
release: false
183+
- name: Dependency Review
184+
type: SCA
185+
rulesets:
186+
- default
187+
results: {}
188+
integration:
189+
adhoc: false
190+
ci: true
191+
release: false

SECURITY.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ If you believe you have found a security vulnerability in any Radius repository,
88

99
**Please do not report security vulnerabilities through public GitHub issues.**
1010

11-
Instead, please report them to the [security@radapp.dev](mailto:security@radapp.dev).
11+
Instead, please report them to the [radiuscoreteam@service.microsoft.com](mailto:radiuscoreteam@service.microsoft.com).
1212

1313
You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message.
1414

0 commit comments

Comments
 (0)