Skip to content

Initial draft of Python 'Security Policy'#1804

Merged
hugovk merged 13 commits into
python:mainfrom
sethmlarson:security-policy
May 27, 2026
Merged

Initial draft of Python 'Security Policy'#1804
hugovk merged 13 commits into
python:mainfrom
sethmlarson:security-policy

Conversation

@sethmlarson
Copy link
Copy Markdown
Contributor

Part of #1803, this is an initial draft of the Python security policy and "limited" threat model that will be expanded and include more details for specific standard library modules and features. The security policy:

  • Prioritizes PSRT members well-being over technical merit of reports.
  • Documents how the Code of Conduct applies to vulnerability reporting communications.
  • Creates a small threat model for the Python interpreter for common reports which are not vulnerabilities. Future threat models will be added to a separate document and linked to.

cc @python/psrt

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.