|
5 | 5 | The SIG Security External Audit subproject (subproject, henceforth) is responsible for coordinating regular,
|
6 | 6 | comprehensive, third-party security audits.
|
7 | 7 | The subproject publishes the deliverables of the audit after abiding to the
|
8 |
| -[Security Release Process](https://github.com/kubernetes/security/blob/master/security-release-process.md) and |
9 |
| -[embargo policy](https://github.com/kubernetes/security/blob/master/private-distributors-list.md#embargo-policy). |
| 8 | +[Security Release Process](https://github.com/kubernetes/committee-security-response/blob/main/security-release-process.md) and |
| 9 | +[embargo policy](https://github.com/kubernetes/committee-security-response/blob/main/private-distributors-list.md#embargo-policy). |
10 | 10 |
|
11 | 11 | - [Request for Proposal (RFP)](#rfp)
|
12 | 12 | - [Security Audit Scope](#security-audit-scope)
|
@@ -53,8 +53,8 @@ The question period is typically open between the RFP's opening date and closing
|
53 | 53 | Proposals are reviewed by the subproject proposal reviewers after the RFP closing date. An understanding of security audits is required to be a proposal reviewer.
|
54 | 54 |
|
55 | 55 | All proposal reviewers must agree to abide by the
|
56 |
| -**[Security Release Process](https://github.com/kubernetes/security/blob/master/security-release-process.md)**, |
57 |
| -**[embargo policy](https://github.com/kubernetes/security/blob/master/private-distributors-list.md#embargo-policy)**, |
| 56 | +**[Security Release Process](https://github.com/kubernetes/committee-security-response/blob/main/security-release-process.md)**, |
| 57 | +**[embargo policy](https://github.com/kubernetes/committee-security-response/blob/main/private-distributors-list.md#embargo-policy)**, |
58 | 58 | and have no [conflict of interest](#conflict-of-interest) the tracking issue.
|
59 | 59 | This is done by placing a comment on the issue associated with the security audit.
|
60 | 60 | e.g. `I agree to abide by the guidelines set forth in the Security Release Process, specifically the embargo on CVE
|
|
0 commit comments