Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up

Security: Pylons/webob

Security

SECURITY.md

To report security issues with projects under the Pylons Project, send email to:pylons-project-security@googlegroups.com.If we determine that your report may be a security issue with the project, we may contact you for further information.We volunteers ask that you delay public disclosure of your report for at least ninety (90) days from the date you report it to us.This will allow sufficient time for us to process your report and coordinate disclosure with you.

Once verified and fixed, the following steps will be taken.

  • We will use GitHub's Security Advisory tool to report the issue.
  • GitHub will review our Security Advisory report for compliance with Common Vulnerabilities and Exposures (CVE) rules.If it is compliant, they will submit it to the MITRE Corporation to generate aCVE.This in turn submits the CVE to theNational Vulnerability Database (NVD).GitHub notifies us of their decision.
  • Assuming it is compliant, we then publish our Security Advisory on GitHub, which triggers the next steps.
  • GitHub will publish the CVE to the CVE List.
  • GitHub will broadcast our Security Advisory via theGitHub Advisory Database.
  • GitHub will sendsecurity alerts to all repositories that use our package (and have opted into security alerts).This includes Dependabot alerts.
  • We will make a bug-fix release.
  • We will send an announcement through our usual channels, including those listed on the Pylons Project website'sContact page.
  • We will provide credit to the reporter or researcher in the vulnerability notice.
Learn more about advisories related toPylons/webob in theGitHub Advisory Database

[8]ページ先頭

©2009-2025 Movatter.jp