-
Notifications
You must be signed in to change notification settings - Fork 3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
How to report a security bug of pip? #11033
Comments
There is no policy in |
security@python.org reject my report because it's not a security bug about python. |
🤷 - no idea then |
cc @pradyunsg we talked about this the other day |
Is there an email like security@python.org to accept report? |
From previous discussion security@python.org is the one to use, and I’m surprised it rejected it (first time I’ve heard that happened). I don’t think there’s another dedicated mailing list for this, the closest alternative would be to find maintainers’ emails on GitHub and email privately. (I’m going to raise this issue in the Packaging Summit next month at PyCon) |
Linking #10928 |
Thanks, I will send the report to you later. |
Closing in favour of #11037, given that OP has reached out. |
I don't see any reports from OP on security@python.org. Could you forward the email that you sent to security@ to me? |
Description
Hello,
I want to know how to report a security bug of pip.
Thank you.
Expected behavior
None
pip version
22.0.4
Python version
3.10.4
OS
windows
How to Reproduce
None
Output
None
Code of Conduct
The text was updated successfully, but these errors were encountered: