Skip to content

Commit 85a3101

Browse files
Use only rudimentary formatting
1 parent c2da1cb commit 85a3101

1 file changed

Lines changed: 9 additions & 25 deletions

File tree

‎.github/VULNERABILITY_REPORT.yml‎

Lines changed: 9 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -4,22 +4,13 @@ body:
44
- type: markdown
55
attributes:
66
value: |
7-
> [!IMPORTANT] Not all bugs are vulnerabilities. Read the [Python security
8-
> policy](https://devguide.python.org/security/policy/)
9-
> before submitting, and evaluate your report against [what types of
10-
> bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities)
11-
> and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports).
7+
**Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports).
128
13-
Python Security Response Team (*PSRT*) members balance this work against
14-
many other responsibilities. Keep the report short and in plain text:
15-
no headers, tables, PDFs, binaries, or severity and CVSS information.
9+
Python Security Response Team (*PSRT*) members balance this work against many other responsibilities. Keep the report short and in plain text: no headers, tables, PDFs, binaries, or severity and CVSS information.
1610
17-
Reports that do not contain a potential security vulnerability will be
18-
discarded without a reply.
11+
Reports that do not contain a potential security vulnerability will be discarded without a reply.
1912
20-
This form is for CPython only. For other projects (such as pip or
21-
python.org), or if you are not sure where to send your report, email
22-
[security@python.org](mailto:security@python.org).
13+
This form is for CPython only. For other projects (such as pip or python.org), or if you are not sure where to send your report, email [security@python.org](mailto:security@python.org).
2314
- type: textarea
2415
id: summary
2516
attributes:
@@ -32,32 +23,25 @@ body:
3223
attributes:
3324
label: Threat model
3425
description: >
35-
What does the attacker control, and what do they gain?
36-
Describe the code, configuration, or deployment that may exist in the real world and is exploitable.
37-
Where possible, cite the relevant part of the
38-
[security policy](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities).
26+
What does the attacker control, and what do they gain? Describe the code, configuration, or deployment that may exist in the real world and is exploitable. Where possible, cite the relevant part of the [security policy](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities).
3927
validations:
4028
required: true
4129
- type: textarea
4230
id: proof_of_concept
4331
attributes:
4432
label: Proof of concept
4533
description: >
46-
A script that reproduces the issue and clearly indicates whether the vulnerability is present,
47-
such as exiting with `1` if vulnerable and `0` if not.
48-
If it depends on a specially constructed binary file, include a script to construct the file rather than the file itself.
49-
Wrap scripts longer than a few lines in a
50-
[collapsed section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections)
51-
using `<details> ... </details>`.
34+
A script that reproduces the issue and clearly indicates whether the vulnerability is present, such as exiting with `1` if vulnerable and `0` if not. If it depends on a specially constructed binary file, include a script to construct the file rather than the file itself.
35+
36+
Wrap scripts longer than a few lines in a [collapsed section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections) using `<details> ... </details>`.
5237
validations:
5338
required: true
5439
- type: input
5540
id: versions
5641
attributes:
5742
label: Python versions tested
5843
description: >
59-
List every version tested and indicate which were found to be vulnerable.
60-
Only [supported versions](https://devguide.python.org/versions/) accept reports.
44+
List every version tested and indicate which were found to be vulnerable. Only [supported versions](https://devguide.python.org/versions/) accept reports.
6145
validations:
6246
required: true
6347
- type: textarea

0 commit comments

Comments
 (0)