Skip to content

Commit d016c90

Browse files
aclark4lifeCopilot
andcommitted
Remove active exploitation escalation bullet from incident response
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent 6a0192a commit d016c90

File tree

1 file changed

+0
-1
lines changed

1 file changed

+0
-1
lines changed

.github/INCIDENT_RESPONSE.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -124,7 +124,6 @@ Vulnerabilities and incidents may be reported or discovered through:
124124
Numbering Authority — no separate MITRE form required). The CVE is reserved privately
125125
and published automatically when the advisory goes public.
126126
6. **Escalation** — Escalate beyond the core maintainer team if any of the following apply:
127-
- The vulnerability is being actively exploited in the wild → notify [GitHub Security](mailto:security@github.com) and the [Python Security Response Team](https://www.python.org/news/security/)
128127
- The fix requires changes to CPython or a dependency outside Pillow's control → contact the relevant upstream immediately
129128
- A legal concern arises (e.g. GDPR-reportable data exposure) → contact the project's legal/fiscal sponsor
130129
- The Incident Lead is unreachable for > 24 hours on a Critical issue → any other maintainer may assume the role

0 commit comments

Comments
 (0)