You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: .github/INCIDENT_RESPONSE.md
-1Lines changed: 0 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -124,7 +124,6 @@ Vulnerabilities and incidents may be reported or discovered through:
124
124
Numbering Authority — no separate MITRE form required). The CVE is reserved privately
125
125
and published automatically when the advisory goes public.
126
126
6.**Escalation** — Escalate beyond the core maintainer team if any of the following apply:
127
-
- The vulnerability is being actively exploited in the wild → notify [GitHub Security](mailto:security@github.com) and the [Python Security Response Team](https://www.python.org/news/security/)
128
127
- The fix requires changes to CPython or a dependency outside Pillow's control → contact the relevant upstream immediately
129
128
- A legal concern arises (e.g. GDPR-reportable data exposure) → contact the project's legal/fiscal sponsor
130
129
- The Incident Lead is unreachable for > 24 hours on a Critical issue → any other maintainer may assume the role
0 commit comments