Skip to content
/ django Public

Added security reporting guidelines.#19201

Merged
sarahboyce merged 3 commits intodjango:mainfrom
sarahboyce:security-reporting-guidelines
Feb 24, 2025
Merged

Added security reporting guidelines.#19201
sarahboyce merged 3 commits intodjango:mainfrom
sarahboyce:security-reporting-guidelines

Conversation

@sarahboyce
Copy link
Contributor

Due to regularly receiving reports which we do not consider to be valid security vulnerabilities, the Django security team wishes to formalize common reporting issues so that they can be linked to when replying to security reports.

@sarahboyce sarahboyce requested a review from a team February 21, 2025 10:38
@github-actions github-actions bot added the no ticket Based on PR title, no linked Trac ticket label Feb 21, 2025
Copy link
Member

@carltongibson carltongibson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good @sarahboyce. Just one tweak...

@sarahboyce sarahboyce force-pushed the security-reporting-guidelines branch from c8534fe to 32a0f4d Compare February 21, 2025 10:44
@sarahboyce sarahboyce force-pushed the security-reporting-guidelines branch from 32a0f4d to bada62a Compare February 21, 2025 11:56
@sarahboyce sarahboyce force-pushed the security-reporting-guidelines branch 2 times, most recently from d289872 to 40db4ff Compare February 21, 2025 13:08
@sarahboyce sarahboyce force-pushed the security-reporting-guidelines branch from 40db4ff to 891dfa1 Compare February 21, 2025 15:49
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It might be worth adding a note that issues resulting from large, but potentially reasonable setting values should be reported using the public tracker for hardening.

Copy link
Member

@cliffordgama cliffordgama left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks great! I've added a few tiny suggestions.

@sarahboyce sarahboyce force-pushed the security-reporting-guidelines branch from 891dfa1 to 3277005 Compare February 21, 2025 16:41
Copy link
Member

@felixxm felixxm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sarahboyce Thanks 👍 Only nitpicks from me 😉

…g content via the DTL.

This also removes the need to add warnings for every Django template filter.
@sarahboyce sarahboyce force-pushed the security-reporting-guidelines branch from 3277005 to b9f9a2d Compare February 22, 2025 06:39
@sarahboyce sarahboyce merged commit 582ba18 into django:main Feb 24, 2025
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no ticket Based on PR title, no linked Trac ticket

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants