Skip to content

Commit c2da1cb

Browse files
Draft VULNERABILITY_REPORT.yml
1 parent 9d3b0b8 commit c2da1cb

1 file changed

Lines changed: 80 additions & 0 deletions

File tree

‎.github/VULNERABILITY_REPORT.yml‎

Lines changed: 80 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,80 @@
1+
name: Vulnerability report
2+
description: Privately report a potential security vulnerability in CPython
3+
body:
4+
- type: markdown
5+
attributes:
6+
value: |
7+
> [!IMPORTANT] Not all bugs are vulnerabilities. Read the [Python security
8+
> policy](https://devguide.python.org/security/policy/)
9+
> before submitting, and evaluate your report against [what types of
10+
> bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities)
11+
> and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports).
12+
13+
Python Security Response Team (*PSRT*) members balance this work against
14+
many other responsibilities. Keep the report short and in plain text:
15+
no headers, tables, PDFs, binaries, or severity and CVSS information.
16+
17+
Reports that do not contain a potential security vulnerability will be
18+
discarded without a reply.
19+
20+
This form is for CPython only. For other projects (such as pip or
21+
python.org), or if you are not sure where to send your report, email
22+
[security@python.org](mailto:security@python.org).
23+
- type: textarea
24+
id: summary
25+
attributes:
26+
label: Summary
27+
description: A few sentences describing the vulnerability.
28+
validations:
29+
required: true
30+
- type: textarea
31+
id: threat_model
32+
attributes:
33+
label: Threat model
34+
description: >
35+
What does the attacker control, and what do they gain?
36+
Describe the code, configuration, or deployment that may exist in the real world and is exploitable.
37+
Where possible, cite the relevant part of the
38+
[security policy](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities).
39+
validations:
40+
required: true
41+
- type: textarea
42+
id: proof_of_concept
43+
attributes:
44+
label: Proof of concept
45+
description: >
46+
A script that reproduces the issue and clearly indicates whether the vulnerability is present,
47+
such as exiting with `1` if vulnerable and `0` if not.
48+
If it depends on a specially constructed binary file, include a script to construct the file rather than the file itself.
49+
Wrap scripts longer than a few lines in a
50+
[collapsed section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections)
51+
using `<details> ... </details>`.
52+
validations:
53+
required: true
54+
- type: input
55+
id: versions
56+
attributes:
57+
label: Python versions tested
58+
description: >
59+
List every version tested and indicate which were found to be vulnerable.
60+
Only [supported versions](https://devguide.python.org/versions/) accept reports.
61+
validations:
62+
required: true
63+
- type: textarea
64+
id: patch
65+
attributes:
66+
label: Suggested fix
67+
description: Ideally, a minimal patch with the mitigation.
68+
validations:
69+
required: false
70+
- type: checkboxes
71+
id: checklist
72+
attributes:
73+
label: Before submitting
74+
options:
75+
- label: I have read the security policy and evaluated this report against it.
76+
required: true
77+
- label: I have checked that this issue is not already resolved on the `main` branch.
78+
required: true
79+
- label: I have verified the factual validity of everything in this report, including any content produced by an LLM.
80+
required: true

0 commit comments

Comments
 (0)