Skip to content

Commit 68be7f3

Browse files
aclark4lifeCopilot
andcommitted
Remove Tidelift notification step from triage
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent e0f9e2b commit 68be7f3

1 file changed

Lines changed: 1 addition & 2 deletions

File tree

.github/INCIDENT_RESPONSE.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -125,8 +125,7 @@ Vulnerabilities and incidents may be reported or discovered through:
125125
5. **Request a CVE** through the GitHub Security Advisory workflow (GitHub is a CVE
126126
Numbering Authority — no separate MITRE form required). The CVE is reserved privately
127127
and published automatically when the advisory goes public.
128-
6. Notify Tidelift if the severity is High or Critical.
129-
7. **Escalation** — Escalate beyond the core maintainer team if any of the following apply:
128+
6. **Escalation** — Escalate beyond the core maintainer team if any of the following apply:
130129
- The vulnerability is being actively exploited in the wild → notify [GitHub Security](mailto:security@github.com) and the [Python Security Response Team](https://www.python.org/news/security/)
131130
- The fix requires changes to CPython or a dependency outside Pillow's control → contact the relevant upstream immediately
132131
- A legal concern arises (e.g. GDPR-reportable data exposure) → contact the project's legal/fiscal sponsor

0 commit comments

Comments
 (0)