Build software better, together

GitHub

GitHub CopilotWrite better code with AI | MCP RegistryIntegrate external tools | ActionsAutomate any workflow | CodespacesInstant dev environments | IssuesPlan and track work | Code ReviewManage code changes | Code QualityEnforce quality at merge | Why GitHub | Marketplace | View all features | Enterprises | Small and medium teams | Startups | View all use cases | View all industries | View all solutions | AI | Software Development | DevOps | Security | View all topics | Customer stories | Events & webinars | Ebooks & reports | Business insights | Trust center | Partners | View all resources

Security Policy

Python

provides a security policy and threat model

in the Python Developer's Guide documenting what bugs are vulnerabilities, how to structure reports, and what versions of Python accept reports.

Python Security Response Team (PSRT) members balance security work against many other responsibilities. Please be thoughtful about the time and attention your report requires. Repeated failure to respect the security policy will result in future reports being rejected, or the reporter being banned from the python GitHub organization, regardless of technical merit.

Reporting a Vulnerability

The

Python security policy

documents

how to submit a vulnerability report

using GitHub Security Advisories. Please read the security policy prior to filing a vulnerability report, especially the section on

what information to include and exclude

in vulnerability reports. Following the security policy means the PSRT can quickly and efficiently triage your report, not following the security policy will only delay triaging your report.