This policy applies to every repository in the KeiaiLab organization
unless a repository ships its own SECURITY.md.
Only the latest minor release of each project receives security fixes. Upgrade to it before reporting.
Do not open a public issue. Report privately through either channel:
- GitHub: the repository's Security tab, then Report a vulnerability (private vulnerability reporting is enabled for the organization).
- Email: support@keiailab.com
Include the affected project and version, reproduction steps, and the impact you observed.
| Step | Target |
|---|---|
| Acknowledgement | 3 business days |
| Fix or advisory (high/critical) | 30 days |
Some charts deploy images that KeiaiLab does not build: mongo,
percona/mongodb_exporter, valkey, and qdrant. These are marked
whitelisted in Artifact Hub. Report their vulnerabilities upstream
and track upstream advisories.
- Helm charts are PGP-signed. The public key is published in each
chart repository (for example
charts/keiailab-helm-signing-public.asc); verify withhelm verifyorhelm pull --verify. - Container images built by KeiaiLab carry build provenance and an SBOM attestation.