Skip to content

Enable GHSAs instead of pointing to security@python.org? #1397

Description

@StanFromIreland

Hello packaging maintainers,

I'd like to encourage you to consider enabling GitHub Security Advisories instead of directing vulnerability reports to security@python.org. This would allow reports to go directly to your maintainer team, while also making it easier to manage collaborators and private forks when developing and reviewing fixes.

If you'd prefer to continue working with the PSRT, I'd suggest we use the same approach there. We've moved to GHSAs for all of our repositories (python/psrt-ghsa-bot#60), largely because of the benefits mentioned above.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions