Security: Line goes up · Hugo van Kemenade

rbanffy1 pts0 comments

Security: line goes up · Hugo van Kemenade&darr;Skip to main content<br>Table of Contents

Like many other projects, CPython is experiencing a huge increase in security reports.<br>CVEs per year #<br>Last month, PSF Security Developer-in-Residence Seth Larson<br>posted a chart of<br>CVEs per year, showing a<br>large increase in 2026:

But this only represents the output of security work, and doesn&rsquo;t show all the work<br>dealing with incoming reports. Many are closed and dealt with as non-security bug<br>reports instead; many are closed as neither security nor bug reports.<br>Let&rsquo;s reveal some of this unseen work by the<br>Python Security Response Team (PSRT).<br>GHSAs by month #<br>Here are the number of incoming GitHub Security Advisories (GHSA) reports created since<br>July 2024:

GHSAs by year #<br>Here is the same thing by year, and remembering we&rsquo;re only halfway through 2026:

Email reports by month #<br>We&rsquo;ve only fairly recently been<br>encouraging new reports be made via<br>GHSA. Before this, they were usually made by email. The next chart is the number of<br>email discussions (or threads) and participants by month:

Thanks #<br>Big thanks to Seth for all his work as Security Developer-in-Residence: helping shepherd<br>all these reports, developing a<br>security policy to improve the quality<br>of incoming reports and help us assess them, and defining PSRT membership and<br>responsibilities via PEP 811 to build an active<br>team. All this would be much harder without his guidance! And thanks to<br>Alpha-Omega for sponsoring his position at the PSF.

Hugo van Kemenade<br>Powered by Hugo & Congo & Hugo

security reports hugo year month work

Related Articles