Hugo van Kemenade: Security: l... Note

Hugo van Kemenade: Security: line goes up

The CPython project is experiencing a significant increase in security reports, similar to other projects. A chart was posted by Seth Larson, the PSF Security Developer-in-Residence, showing a large increase in CVEs per year, with a notable spike in 2026. However, this chart only represents the output of security work and does not account for all the work involved in dealing with incoming reports. Many reports are closed and dealt with as non-security bug reports or neither security nor bug reports. The Python Security Response Team, or PSRT, is responsible for handling these reports, and their work is not fully reflected in the CVE chart. The number of incoming GitHub Security Advisories, or GHSAs, has been tracked since July 2024, and the data shows a significant number of reports. The GHSAs are also tracked by year, with the data for 2026 only being halfway complete. In addition to GHSAs, email reports were also used to submit security reports, and the number of email discussions and participants has been tracked by month. The PSF is grateful for the work of Seth Larson, who has helped to develop a security policy and define PSRT membership and responsibilities. Overall, the increase in security reports and the work of the PSRT are important for maintaining the security and integrity of the CPython project.
CdXz5zHNQW_JoaL6a52nC.png