Skip to content

Update security policy#9552

Merged
aclark4life merged 4 commits intomainfrom
security-policy
Apr 8, 2026
Merged

Update security policy#9552
aclark4life merged 4 commits intomainfrom
security-policy

Conversation

@aclark4life
Copy link
Copy Markdown
Member

Changes proposed in this pull request:

  • Prefer Private vulnerability reporting but keep Tidelift for folks that cannot use GitHub.

aclark4life and others added 3 commits April 8, 2026 14:52
Co-authored-by: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com>
Co-authored-by: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com>
Co-authored-by: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com>
Copy link
Copy Markdown
Member

@hugovk hugovk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@aclark4life aclark4life merged commit 77b2f67 into main Apr 8, 2026
96 checks passed
@aclark4life aclark4life deleted the security-policy branch April 8, 2026 20:23
# Security policy

To report sensitive vulnerability information, please use the [Tidelift security contact](https://tidelift.com/security). Tidelift will coordinate the fix and disclosure.
To report sensitive vulnerability information, report it [privately on GitHub](https://github.com/python-pillow/Pillow/security).
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When logged out, if you go to https://github.com/python-pillow/Pillow/security now, you see this file, and clicking on 'privately on GitHub' just reloads the page.

Shouldn't this be the link used by the 'Report a vulnerability' button? https://github.com/python-pillow/Pillow/security/advisories/new

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably yes and sorry, was going to send a new PR, but accidentally committed to main: b97034a.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants