Buildpacks has completed a security self-assessment and made it publicly available as a document:
For CNCF Graduation, security self-assessments are typically published as Markdown files in a CNCF-discoverable repository to improve transparency, long-term accessibility, and reviewability (example: cncf/toc#1986).
It would be helpful to:
- Convert the existing Buildpacks security self-assessment to a Markdown (.md) format.
- Check it into an appropriate repo (cncf/toc via PR) following established precedent.
- Link to the checked-in assessment from Buildpacks security documentation for easy discovery.
This would align Buildpacks with TAG-Security guidance and common CNCF practice, while preserving the excellent work already done in the current assessment.