Add a template for GHSAs - #158612
Open
StanFromIreland wants to merge 4 commits into
Open
Add a template for GHSAs#158612StanFromIreland wants to merge 4 commits into
StanFromIreland wants to merge 4 commits into
Conversation
StanFromIreland
requested review from
AA-Turner,
JacobCoffee,
ezio-melotti,
hugovk,
itamaro and
webknjaz
as code owners
October 2, 2026 17:17
ezio-melotti
reviewed
Oct 2, 2026
| - type: markdown | ||
| attributes: | ||
| value: | | ||
| **Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). |
Member
There was a problem hiding this comment.
This paragraph sounds a bit "aggressive". Maybe something like:
Suggested change
| **Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). | |
| This form is for reporting CPython vulnerabilities only. Before submitting read the [Python security policy](https://devguide.python.org/security/policy/), make sure that [the issue you are reporting is a vulnerability](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities), and check what [versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). |
or
Suggested change
| **Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). | |
| This form is for reporting CPython vulnerabilities only. Before submitting: | |
| * read the [Python security policy](https://devguide.python.org/security/policy/); | |
| * make sure that [the issue you are reporting is a vulnerability](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities); | |
| * check what [versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). |
Since all 3 links link to the same page, and the two linked sections are right there, you could summarize it with:
Suggested change
| **Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). | |
| This form is for reporting CPython vulnerabilities only. Before submitting, read the [Python security policy](https://devguide.python.org/security/policy/) to understand which issues are vulnerabilities, what versions of Python accept reports, and how to report the problem effectively. |
Member
Author
There was a problem hiding this comment.
Maybe it is a little aggressive, but I’m afraid that may be becoming necessary. It also the same in our security policy.
Unfortunately, we do occasionally get reports where the reporter is quite aggressive or rude, so I think it’s reasonable for the template to set clear expectations and boundaries.
I applied the suggestion to reduce links.
Co-authored-by: Ezio Melotti <ezio.melotti@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CC @python/psrt
This feature was released yesterday, and to be frank, it's a little rudimentary. It has limited support for markdown (we can't wrap text, or use some features), and is not fully customisable, as some sections can't be disabled.
I tried to base the template on what we recommend in our security policy, I also tried to link to it so that hopefully people read it.
See the current format: https://github.com/python/cpython/security/advisories/new
Preview: https://github.com/StanFromIreland/cpython-ci-testing/security/advisories/new