Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 7 additions & 3 deletions security/psrt.rst
Original file line number Diff line number Diff line change
Expand Up @@ -236,13 +236,13 @@ This patch can then be applied and pushed to the public GitHub repository:
git apply ./ghsa-abcd-efgh-ijkl.patch
git push origin branch-name

.. warning:: **IMPORTANT:** CPython's backport infrastructure
.. important:: CPython's backport infrastructure
is used for tracking backported patches. Use **one GitHub issue
per CVE** to accurately track backports of vulnerability fixes.
For new CVEs, even when related to a previous issue, **open a
new GitHub issue** to accurately track fixed versions.

.. warning:: **IMPORTANT:** Don't select the green 'Merge pull request'
.. important:: Don't select the green 'Merge pull request'
Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

And a bonus change! This seemed a little odd, so I changed it to just important.

or 'Publish advisory' buttons within GHSA. Advisories are published
to the mailing list, and the 'Merge pull request' button within
GHSA bypasses all continuous integration and branch protection
Expand Down Expand Up @@ -323,7 +323,11 @@ Submit using GitHub Security Advisories

Thanks for submitting this report.
We use GitHub Security Advisories for triaging vulnerability reports,
please submit your report here:
please review our security policy before submitting:

https://devguide.python.org/security/policy/
Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could also link directly to https://devguide.python.org/security/policy/#what-to-include-and-how-to-structure-a-vulnerability-report, but the rest (e.g. the CoC) is useful too.


Then submit your report here:

https://github.com/python/cpython/security/advisories/new

Expand Down
Loading