You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
> before submitting, and evaluate your report against [what types of
10
-
> bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities)
11
-
> and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports).
7
+
**Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports).
12
8
13
-
Python Security Response Team (*PSRT*) members balance this work against
14
-
many other responsibilities. Keep the report short and in plain text:
15
-
no headers, tables, PDFs, binaries, or severity and CVSS information.
9
+
Python Security Response Team (*PSRT*) members balance this work against many other responsibilities. Keep the report short and in plain text: no headers, tables, PDFs, binaries, or severity and CVSS information.
16
10
17
-
Reports that do not contain a potential security vulnerability will be
18
-
discarded without a reply.
11
+
Reports that do not contain a potential security vulnerability will be discarded without a reply.
19
12
20
-
This form is for CPython only. For other projects (such as pip or
21
-
python.org), or if you are not sure where to send your report, email
This form is for CPython only. For other projects (such as pip or python.org), or if you are not sure where to send your report, email [security@python.org](mailto:security@python.org).
23
14
- type: textarea
24
15
id: summary
25
16
attributes:
@@ -32,32 +23,25 @@ body:
32
23
attributes:
33
24
label: Threat model
34
25
description: >
35
-
What does the attacker control, and what do they gain?
36
-
Describe the code, configuration, or deployment that may exist in the real world and is exploitable.
What does the attacker control, and what do they gain? Describe the code, configuration, or deployment that may exist in the real world and is exploitable. Where possible, cite the relevant part of the [security policy](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities).
39
27
validations:
40
28
required: true
41
29
- type: textarea
42
30
id: proof_of_concept
43
31
attributes:
44
32
label: Proof of concept
45
33
description: >
46
-
A script that reproduces the issue and clearly indicates whether the vulnerability is present,
47
-
such as exiting with `1` if vulnerable and `0` if not.
48
-
If it depends on a specially constructed binary file, include a script to construct the file rather than the file itself.
A script that reproduces the issue and clearly indicates whether the vulnerability is present, such as exiting with `1` if vulnerable and `0` if not. If it depends on a specially constructed binary file, include a script to construct the file rather than the file itself.
35
+
36
+
Wrap scripts longer than a few lines in a [collapsed section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections) using `<details> ... </details>`.
52
37
validations:
53
38
required: true
54
39
- type: input
55
40
id: versions
56
41
attributes:
57
42
label: Python versions tested
58
43
description: >
59
-
List every version tested and indicate which were found to be vulnerable.
60
-
Only [supported versions](https://devguide.python.org/versions/) accept reports.
44
+
List every version tested and indicate which were found to be vulnerable. Only [supported versions](https://devguide.python.org/versions/) accept reports.
0 commit comments