Hello packaging maintainers,
I'd like to encourage you to consider enabling GitHub Security Advisories instead of directing vulnerability reports to security@python.org. This would allow reports to go directly to your maintainer team, while also making it easier to manage collaborators and private forks when developing and reviewing fixes.
If you'd prefer to continue working with the PSRT, I'd suggest we use the same approach there. We've moved to GHSAs for all of our repositories (python/psrt-ghsa-bot#60), largely because of the benefits mentioned above.
Hello packaging maintainers,
I'd like to encourage you to consider enabling GitHub Security Advisories instead of directing vulnerability reports to security@python.org. This would allow reports to go directly to your maintainer team, while also making it easier to manage collaborators and private forks when developing and reviewing fixes.
If you'd prefer to continue working with the PSRT, I'd suggest we use the same approach there. We've moved to GHSAs for all of our repositories (python/psrt-ghsa-bot#60), largely because of the benefits mentioned above.