## Security Microsoft dey take di security of dia software products and services serious, e include all di source code repositories wey dem dey manage through dia GitHub organizations, wey include [Microsoft](https://github.com/Microsoft), [Azure](https://github.com/Azure), [DotNet](https://github.com/dotnet), [AspNet](https://github.com/aspnet), [Xamarin](https://github.com/xamarin), and [our GitHub organizations](https://opensource.microsoft.com/). If you feel say you don find security wahala for any Microsoft-owned repository wey match [Microsoft's definition of a security vulnerability](https://docs.microsoft.com/en-us/previous-versions/tn-archive/cc751383(v=technet.10)), abeg report am to us as we describe below. ## How to Report Security Wahala **Abeg no report security wahala through public GitHub issues.** Instead, abeg report am to di Microsoft Security Response Center (MSRC) for [https://msrc.microsoft.com/create-report](https://msrc.microsoft.com/create-report). If you wan submit am without logging in, send email go [secure@microsoft.com](mailto:secure@microsoft.com). If e possible, encrypt your message with our PGP key; abeg download am from di [Microsoft Security Response Center PGP Key page](https://www.microsoft.com/en-us/msrc/pgp-key-msrc). You suppose get response within 24 hours. If for any reason you no get response, abeg follow up with email to make sure say we receive your original message. You fit find more info for [microsoft.com/msrc](https://www.microsoft.com/msrc). Abeg include di information wey we request below (as much as you fit provide) to help us understand di nature and scope of di wahala: * Di type of wahala (e.g. buffer overflow, SQL injection, cross-site scripting, etc.) * Full paths of di source file(s) wey relate to di wahala * Di location of di affected source code (tag/branch/commit or direct URL) * Any special configuration wey dem need to reproduce di wahala * Step-by-step instructions to reproduce di wahala * Proof-of-concept or exploit code (if e possible) * Di impact of di wahala, including how attacker fit use am Dis info go help us triage your report quick. If you dey report for bug bounty, di more complete your report be, di higher di bounty award fit be. Abeg visit our [Microsoft Bug Bounty Program](https://microsoft.com/msrc/bounty) page for more details about di programs wey dey active. ## Preferred Languages We go like make all communication dey for English. ## Policy Microsoft dey follow di principle of [Coordinated Vulnerability Disclosure](https://www.microsoft.com/en-us/msrc/cvd). --- **Disclaimer**: Dis docu don dey translate wit AI translation service [Co-op Translator](https://github.com/Azure/co-op-translator). Even though we dey try make am accurate, abeg sabi say automated translation fit get mistake or no correct well. Di original docu for im native language na di main correct source. For important information, e good make una use professional human translation. We no go fit take blame for any misunderstanding or wrong interpretation wey fit happen because of dis translation.