https://github.com/python/cpython/commit/2cd747b89bd5e0ad06edc506bb62a7c5e40e02cc
commit: 2cd747b89bd5e0ad06edc506bb62a7c5e40e02cc
branch: main
author: Stan Ulbrych <[email protected]>
committer: StanFromIreland <[email protected]>
date: 2026-10-08T21:03:51+01:00
summary:

Add a template for GHSAs (#158612)

Co-authored-by: Ezio Melotti <[email protected]>

files:
A .github/VULNERABILITY_REPORT.yml

diff --git a/.github/VULNERABILITY_REPORT.yml b/.github/VULNERABILITY_REPORT.yml
new file mode 100644
index 000000000000000..2887c7092d19fe1
--- /dev/null
+++ b/.github/VULNERABILITY_REPORT.yml
@@ -0,0 +1,73 @@
+name: Vulnerability report
+description: Privately report a potential security vulnerability in CPython
+body:
+  - type: markdown
+    attributes:
+      value: |
+        **Not all bugs are vulnerabilities.** Before submitting, read the 
[Python security policy](https://devguide.python.org/security/policy/) to 
understand which issues are vulnerabilities and what versions of Python accept 
reports.
+
+        Keep the report short and in plain text: no headers, tables, PDFs, 
binaries, or severity and CVSS information.
+
+        Reports that do not contain a potential security vulnerability will be 
discarded without a reply.
+
+        To report vulnerabilities that affect other projects (such as pip or 
python.org), or if you are not sure where to send your report, email 
[[email protected]](mailto:[email protected]).
+  - type: textarea
+    id: summary
+    attributes:
+      label: Summary
+      description: A few sentences describing the vulnerability.
+    validations:
+      required: true
+  - type: textarea
+    id: threat_model
+    attributes:
+      label: Threat model
+      description: >
+        What does the attacker control, and what do they gain? Describe the 
code, configuration, or deployment that may exist in the real world and is 
exploitable. Where possible, cite the relevant part of the [security 
policy](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities).
+    validations:
+      required: true
+  - type: textarea
+    id: proof_of_concept
+    attributes:
+      label: Proof of concept
+      description: >
+        A script that reproduces the issue and clearly indicates whether the 
vulnerability is present, such as exiting with `1` if vulnerable and `0` if 
not. If it depends on a specially constructed binary file, include a script to 
construct the file rather than the file itself.
+
+        Wrap scripts longer than a few lines in a [collapsed 
section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections)
 using `<details> ... </details>`.
+    validations:
+      required: true
+  - type: dropdown
+    id: versions
+    attributes:
+      label: "CPython versions tested on:"
+      description: >
+        If any tested version was not vulnerable, say which in the summary. 
Only [supported versions](https://devguide.python.org/versions/) accept reports.
+      multiple: true
+      options:
+        - "3.11"
+        - "3.12"
+        - "3.13"
+        - "3.14"
+        - "3.15"
+        - "3.16"
+        - "CPython main branch"
+    validations:
+      required: true
+  - type: textarea
+    id: patch
+    attributes:
+      label: Suggested fix
+      description: Ideally, a minimal patch with the mitigation.
+    validations:
+      required: false
+  - type: checkboxes
+    id: checklist
+    attributes:
+      label: Before submitting
+      options:
+        - label: I have read the security policy and evaluated this report 
against it.
+          required: true
+        - label: I have checked that this issue is not already resolved on the 
`main` branch.
+          required: true
+        - label: I have verified the factual validity of everything in this 
report, including any content produced by an LLM.
+          required: true

_______________________________________________
Python-checkins mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/python-checkins.python.org
Member address: [email protected]

Reply via email to