So You Received a Security Report. Now What?

133 · Thephp · Aug. 19, 2026, 7:44 p.m.
Summary
This comprehensive guide for PHP project maintainers outlines steps to effectively handle security reports, emphasizing the importance of coordinated disclosure, validating claims, and safely managing proof-of-concept code. It offers a structured process to address vulnerabilities, including communication with reporters, private fixes, and publishing advisories to protect users, while also suggesting long-term improvements for security postures.