Skip to content

Commit 2cd747b

Browse files
Add a template for GHSAs (#158612)
Co-authored-by: Ezio Melotti <ezio.melotti@gmail.com>
1 parent e2c3c7e commit 2cd747b

1 file changed

Lines changed: 73 additions & 0 deletions

File tree

‎.github/VULNERABILITY_REPORT.yml‎

Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
name: Vulnerability report
2+
description: Privately report a potential security vulnerability in CPython
3+
body:
4+
- type: markdown
5+
attributes:
6+
value: |
7+
**Not all bugs are vulnerabilities.** Before submitting, read the [Python security policy](https://devguide.python.org/security/policy/) to understand which issues are vulnerabilities and what versions of Python accept reports.
8+
9+
Keep the report short and in plain text: no headers, tables, PDFs, binaries, or severity and CVSS information.
10+
11+
Reports that do not contain a potential security vulnerability will be discarded without a reply.
12+
13+
To report vulnerabilities that affect other projects (such as pip or python.org), or if you are not sure where to send your report, email [security@python.org](mailto:security@python.org).
14+
- type: textarea
15+
id: summary
16+
attributes:
17+
label: Summary
18+
description: A few sentences describing the vulnerability.
19+
validations:
20+
required: true
21+
- type: textarea
22+
id: threat_model
23+
attributes:
24+
label: Threat model
25+
description: >
26+
What does the attacker control, and what do they gain? Describe the code, configuration, or deployment that may exist in the real world and is exploitable. Where possible, cite the relevant part of the [security policy](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities).
27+
validations:
28+
required: true
29+
- type: textarea
30+
id: proof_of_concept
31+
attributes:
32+
label: Proof of concept
33+
description: >
34+
A script that reproduces the issue and clearly indicates whether the vulnerability is present, such as exiting with `1` if vulnerable and `0` if not. If it depends on a specially constructed binary file, include a script to construct the file rather than the file itself.
35+
36+
Wrap scripts longer than a few lines in a [collapsed section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections) using `<details> ... </details>`.
37+
validations:
38+
required: true
39+
- type: dropdown
40+
id: versions
41+
attributes:
42+
label: "CPython versions tested on:"
43+
description: >
44+
If any tested version was not vulnerable, say which in the summary. Only [supported versions](https://devguide.python.org/versions/) accept reports.
45+
multiple: true
46+
options:
47+
- "3.11"
48+
- "3.12"
49+
- "3.13"
50+
- "3.14"
51+
- "3.15"
52+
- "3.16"
53+
- "CPython main branch"
54+
validations:
55+
required: true
56+
- type: textarea
57+
id: patch
58+
attributes:
59+
label: Suggested fix
60+
description: Ideally, a minimal patch with the mitigation.
61+
validations:
62+
required: false
63+
- type: checkboxes
64+
id: checklist
65+
attributes:
66+
label: Before submitting
67+
options:
68+
- label: I have read the security policy and evaluated this report against it.
69+
required: true
70+
- label: I have checked that this issue is not already resolved on the `main` branch.
71+
required: true
72+
- label: I have verified the factual validity of everything in this report, including any content produced by an LLM.
73+
required: true

0 commit comments

Comments
 (0)