Repository navigation
Add a template for GHSAs - #158612
Add a template for GHSAs#158612
Conversation
| - type: markdown | ||
| attributes: | ||
| value: | | ||
| **Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). |
There was a problem hiding this comment.
This paragraph sounds a bit "aggressive". Maybe something like:
| **Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). | |
| This form is for reporting CPython vulnerabilities only. Before submitting read the [Python security policy](https://devguide.python.org/security/policy/), make sure that [the issue you are reporting is a vulnerability](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities), and check what [versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). |
or
| **Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). | |
| This form is for reporting CPython vulnerabilities only. Before submitting: | |
| * read the [Python security policy](https://devguide.python.org/security/policy/); | |
| * make sure that [the issue you are reporting is a vulnerability](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities); | |
| * check what [versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). |
Since all 3 links link to the same page, and the two linked sections are right there, you could summarize it with:
| **Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). | |
| This form is for reporting CPython vulnerabilities only. Before submitting, read the [Python security policy](https://devguide.python.org/security/policy/) to understand which issues are vulnerabilities, what versions of Python accept reports, and how to report the problem effectively. |
There was a problem hiding this comment.
Maybe it is a little aggressive, but I’m afraid that may be becoming necessary. It also the same in our security policy.
Unfortunately, we do occasionally get reports where the reporter is quite aggressive or rude, so I think it’s reasonable for the template to set clear expectations and boundaries.
I applied the suggestion to reduce links.
Co-authored-by: Ezio Melotti <[email protected]>
|
LGTM |
woodruffw
left a comment
There was a problem hiding this comment.
LGTM, no major notes.
(One thing to consider: some people use LLMs to translate because they're not confident in English, I've found it helpful to tell them to paste their native language in a blockquote so that it can be cross-checked against the machine translation. Doesn't seem critical to include in an initial template, though.)
CC @python/psrt
This feature was released yesterday, and to be frank, it's a little rudimentary. It has limited support for markdown (we can't wrap text, or use some features), and is not fully customisable, as some sections can't be disabled.
I tried to base the template on what we recommend in our security policy, I also tried to link to it so that hopefully people read it.
See the current format: https://github.com/python/cpython/security/advisories/new
Preview: https://github.com/StanFromIreland/cpython-ci-testing/security/advisories/new