-
Notifications
You must be signed in to change notification settings - Fork 3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Document where security issues should be reported #11037
Comments
Also discussed in #10928 |
Is this issue still open for contribution - Changes in documentation to add contact for reporting to security issues |
Yes, we need to document that security issues should be reported to security@python.org |
This is my first contribution , so should i make changes in https://github.com/pypa/pip/blob/main/docs/html/index.md Old content: GitHub Issues New content: GitHub Issues < new content here> |
@pradyunsg ,Pull Request: #11140 |
I guess this can be closed now |
What's the problem this feature will solve?
It’s unclear to users/researchers where they should report security issues in pip.
Describe the solution you'd like
Document that they should email security@python.org with their report and reproducer.
Alternative Solutions
Not documenting it, or listing specific maintainers as security contacts.
Additional context
#11033
Code of Conduct
The text was updated successfully, but these errors were encountered: