Skip to content

Introduce a Security Vulnerability Reporting page#646

Merged
swissspidy merged 2 commits into
wp-cli:mainfrom
johnbillion:vulnerability-reporting
Jun 9, 2026
Merged

Introduce a Security Vulnerability Reporting page#646
swissspidy merged 2 commits into
wp-cli:mainfrom
johnbillion:vulnerability-reporting

Conversation

@johnbillion

Copy link
Copy Markdown
Contributor

As discussed in Slack.

This introduces a page that documents categories of security vulnerability reports that may be technically valid in isolation but violate no realistic threat model. The volume of such reports that the WordPress security team receives is still mostly manageable, but it's increasing along with the rate of AI-driven vulnerability reports.

This can serve as a central place to direct humans and bots that submit such reports.

Use of AI

Claude Code was used to draft the first version of this page. It did an ok job, but I essentially rewrote it to sound more human and trimmed out all the fluff.

@johnbillion johnbillion requested a review from a team as a code owner June 8, 2026 22:38

@BrianHenryIE BrianHenryIE left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reads as reasonable.

As discussed in Slack.

In a private channel? I don't see it when I search.

@swissspidy

Copy link
Copy Markdown
Member

Reads as reasonable.

As discussed in Slack.

In a private channel? I don't see it when I search.

Indeed it was a private chat, accompanied by an in-person conversation at WCEU the other day.

@swissspidy swissspidy merged commit 2a80663 into wp-cli:main Jun 9, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants