- Subscribe to kubernetes-security-announce for ecosystem-wide advisories that might also affect this fork.
- Watch the releases page for redevops.io patch notifications.
- Follow the
#redevops-ingresschannel on the Kubernetes Slack for real-time maintenance updates.
We strongly prefer coordinated disclosure. Choose whichever option is most convenient:
- Use GitHub's private vulnerability reporting feature. Reports opened there are visible only to the maintainer team.
- Email
support@redevops.iowith the details. Encrypting the report with the maintainer PGP key (available in the repository's Security tab) is appreciated but not required.
Please include:
- A description of the issue and the ingress-nginx versions affected
- Reproduction steps or proof-of-concept
- The Kubernetes version(s) and cloud/distribution you tested on
We aim to acknowledge new reports within two business days and provide a remediation plan within seven days. If the issue also affects the upstream Kubernetes project we will coordinate disclosure with the SIG-Network/SIG-Security maintainers.
The redevops.io fork supports the active patch release for each maintained minor listed in the README's compatibility
table. At any point in time this corresponds to the three most recent Kubernetes minors (n, n-1, n-2). Older
branches may receive best-effort fixes for critical CVEs but are not covered by SLA.
For broader Kubernetes version policies, consult the Kubernetes version and version skew support policy.