Files
minio/SECURITY.md
T
Feng Ruohang 15090dc4fd docs: retire migrated working material and clarify documentation ownership
Remove migrated investigation and security documents, repair their incoming links, and align the English/Chinese READMEs with current module and release boundaries. Track AGENTS.md as the shared repository guide and make CLAUDE.md import it; keep working artifacts outside the repository.

Publish pgsty/silo.pgsty.com commit c7682185e2832b981629e1c17aef74fc778c6ca1 before publishing this cleanup: the new documentation routes are not live yet.

Validation: make rebrand-guard; 92 Markdown files checked for deletion-induced broken relative paths; 199 source-to-site references and anchors resolve in the paired site build; git diff --check.
Signed-off-by: Feng Ruohang <rh@vonng.com>
2026-09-16 11:22:48 +08:00

2.5 KiB

Security Policy

Silo is an independent, community-maintained object-storage server derived from the open-source MinIO server. Upstream MinIO security contacts do not handle Silo-specific fixes or release notes.

Supported Versions

Security fixes are tracked on the active development branch and summarized in the security advisory ledger. Only the current Silo release line is supported unless an advisory says otherwise.

Inherited Fix Evidence

The canonical ledger also records security fixes inherited from upstream when they are part of the Silo release baseline. Source and fork commits are linked separately even when the fork preserves the original commit object and SHA.

Reporting a Vulnerability

For vulnerabilities in this fork:

  1. Follow the fork-specific expectations in VULNERABILITY_REPORT.md.
  2. Prefer this repository's private GitHub security advisory workflow.
  3. If private reporting is unavailable, contact the maintainers through the repository without publishing exploit details until a private channel is established.
  4. If you confirm the issue also affects upstream minio/minio, report it upstream separately.

Disclosure Process

Fork-specific fixes and user-visible upgrade notes are published in the security advisory ledger. The fork-specific triage and remediation process is described in VULNERABILITY_REPORT.md.