
Hi,
this is going through the news right now. Has anybody contact us about the bug bounty program for Python?
Christian

On 07.11.2013 11:40, Christian Heimes wrote:
Hi,
this is going through the news right now. Has anybody contact us about the bug bounty program for Python?
FWIW, the PSF was not contacted about this in advance.
Sounds like a nice project, though.

Am 07.11.2013 11:45, schrieb M.-A. Lemburg:
On 07.11.2013 11:40, Christian Heimes wrote:
Hi,
this is going through the news right now. Has anybody contact us about the bug bounty program for Python?
FWIW, the PSF was not contacted about this in advance.
Sounds like a nice project, though.
The PSRT wasn't contacted either.
I like it, it's a great idea! It just came as a surprise to me. Should we contact them and establish a work flow?
Christian

Yes, we probably should. The Django project was contacted by them, I've we've been working with them to set up a workflow, when I saw this I'd assumed someone had been contacted for CPython.
Alex
On Thu, Nov 7, 2013 at 3:24 AM, Christian Heimes christian@cheimes.dewrote:
Am 07.11.2013 11:45, schrieb M.-A. Lemburg:
On 07.11.2013 11:40, Christian Heimes wrote:
Hi,
this is going through the news right now. Has anybody contact us about the bug bounty program for Python?
FWIW, the PSF was not contacted about this in advance.
Sounds like a nice project, though.
The PSRT wasn't contacted either.
I like it, it's a great idea! It just came as a surprise to me. Should we contact them and establish a work flow?
Christian _______________________________________________ python-committers mailing list python-committers@python.org https://mail.python.org/mailman/listinfo/python-committers

On 07.11.2013 12:24, Christian Heimes wrote:
Am 07.11.2013 11:45, schrieb M.-A. Lemburg:
On 07.11.2013 11:40, Christian Heimes wrote:
Hi,
this is going through the news right now. Has anybody contact us about the bug bounty program for Python?
FWIW, the PSF was not contacted about this in advance.
Sounds like a nice project, though.
The PSRT wasn't contacted either.
I like it, it's a great idea! It just came as a surprise to me. Should we contact them and establish a work flow?
I think that would be useful to make sure that the security issues found in the code can be handled properly.
participants (3)
-
Alex Gaynor
-
Christian Heimes
-
M.-A. Lemburg