Skip to content

Add a template for GHSAs - #158612

Open
StanFromIreland wants to merge 4 commits into
python:mainfrom
StanFromIreland:vuln-template
Open

StanFromIreland wants to merge 4 commits into
python:mainfrom
StanFromIreland:vuln-template

Conversation

@StanFromIreland

Copy link
Copy Markdown
Member

CC @python/psrt

This feature was released yesterday, and to be frank, it's a little rudimentary. It has limited support for markdown (we can't wrap text, or use some features), and is not fully customisable, as some sections can't be disabled.

I tried to base the template on what we recommend in our security policy, I also tried to link to it so that hopefully people read it.

See the current format: https://github.com/python/cpython/security/advisories/new

Preview: https://github.com/StanFromIreland/cpython-ci-testing/security/advisories/new

Comment thread .github/VULNERABILITY_REPORT.yml Outdated
- type: markdown
attributes:
value: |
**Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This paragraph sounds a bit "aggressive". Maybe something like:

Suggested change
**Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports).
This form is for reporting CPython vulnerabilities only. Before submitting read the [Python security policy](https://devguide.python.org/security/policy/), make sure that [the issue you are reporting is a vulnerability](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities), and check what [versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports).

or

Suggested change
**Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports).
This form is for reporting CPython vulnerabilities only. Before submitting:
* read the [Python security policy](https://devguide.python.org/security/policy/);
* make sure that [the issue you are reporting is a vulnerability](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities);
* check what [versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports).

Since all 3 links link to the same page, and the two linked sections are right there, you could summarize it with:

Suggested change
**Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports).
This form is for reporting CPython vulnerabilities only. Before submitting, read the [Python security policy](https://devguide.python.org/security/policy/) to understand which issues are vulnerabilities, what versions of Python accept reports, and how to report the problem effectively.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe it is a little aggressive, but I’m afraid that may be becoming necessary. It also the same in our security policy.

Unfortunately, we do occasionally get reports where the reporter is quite aggressive or rude, so I think it’s reasonable for the template to set clear expectations and boundaries.

I applied the suggestion to reduce links.

Comment thread .github/VULNERABILITY_REPORT.yml Outdated
Comment thread .github/VULNERABILITY_REPORT.yml Outdated
Comment thread .github/VULNERABILITY_REPORT.yml
Co-authored-by: Ezio Melotti <ezio.melotti@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

awaiting core review infra CI, GitHub Actions, buildbots, Dependabot, etc. skip issue skip news

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants