Skip to content

Add SECURITY.md#21770

Closed
BHUVANSH855 wants to merge 1 commit into
python:masterfrom
BHUVANSH855:fix-21763-security-policy
Closed

Add SECURITY.md#21770
BHUVANSH855 wants to merge 1 commit into
python:masterfrom
BHUVANSH855:fix-21763-security-policy

Conversation

@BHUVANSH855

Copy link
Copy Markdown

The Python Security Response Team (PSRT), which currently handles security reporting for this project, prefers to receive vulnerability reports through GitHub Security Advisories (GHSAs), rather than by email at security@python.org. For more background, see python/psrt-ghsa-bot#60.

This PR adds a small SECURITY.md file with reporting instructions for the unlikely event that someone needs to report a vulnerability in this repository. It explains where to report vulnerabilities, how to submit a report, and includes a brief note about respectful communication. The content is largely based on CPython's SECURITY.md and security policy.

Even if this repository has not previously received vulnerability reports, this PR provides a proactive reporting path so that, if a report is ever submitted, it reaches the right people through the PSRT's preferred process.

GHSAs are not currently enabled for this repository. Once enabled, they are only visible to people with admin privileges on the repository. To ensure the PSRT can access new reports, the PSRT maintains a bot, python/psrt-ghsa-bot, which automatically adds the team as collaborators when a new report is submitted.

If there are no objections from the maintainers, the organisation administrators will enable GHSAs in this repository and configure the bot.

Closes #21763.

@A5rocks

A5rocks commented Jul 24, 2026

Copy link
Copy Markdown
Collaborator

We are going to decouple from PSRT. Anyways, this PR is unnecessary. Let's see what interface GitHub shows once the setting is enabled.

@A5rocks A5rocks closed this Jul 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Please add a security policy

2 participants