[llvm] 2025 Security Response Group Transparency Report (PR #194066)
Tulio Magno Quites Machado Filho via llvm-commits
llvm-commits at lists.llvm.org
Mon Apr 27 05:07:34 PDT 2026
================
@@ -355,3 +355,131 @@ as part of migrating to GitHub's “security advisory”-based reporting:
GHSA-82m9-xvw3-rvpv
2. “Test that a non-admin can create an advisory (no vulnerability).” |br|
GHSA-34gr-6c7h-cc93
+
+2025
+----
+
+Introduction
+^^^^^^^^^^^^
+
+2025 was the first year all reports were submitted using Github. We report on
+the issues the group received in 2025, or on issues that were received
+earlier, but were disclosed in 2025.
+
+We group the issues into the following categories:
+
+1. Security issues fixed under a coordinated disclosure process (2 issues)
+2. Supply chain security related issues and project services-related issues
+ (2 issues)
+3. Issues deemed to not require coordinated action before disclosing publicly
+ (11 issues)
+4. Invalid issues (5 issues)
+
+In 2025, we received 2 invalid issues that we believe that have been created
+automatically and 1 issue appeared to be created using generative AI. That
+issue was considered to be invalid.
+
+Security issues fixed under a coordinated disclosure process
+^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
+
+This section lists the reported issues where we ended up implementing fixes
+under a coordinated disclosure process. The security advisories for those
+issues at https://github.com/llvm/llvm-security-repo/security/advisories/.
----------------
tuliom wrote:
Agreed. Fixed.
https://github.com/llvm/llvm-project/pull/194066
More information about the llvm-commits
mailing list