3.2 KiB
Security
Microsoft dey take di security of dia software products and services serious, wey include all di source code repositories wey dem dey manage through dia GitHub organizations, wey include Microsoft, Azure, DotNet, AspNet, Xamarin, and our GitHub organizations.
If you feel say you don see security wahala for any Microsoft-owned repository wey match Microsoft's definition of a security vulnerability, abeg report am to us as we go explain below.
How to Report Security Wahala
Abeg no report security wahala through public GitHub issues.
Instead, abeg report am to di Microsoft Security Response Center (MSRC) for https://msrc.microsoft.com/create-report.
If you wan submit without logging in, send email go secure@microsoft.com. If e possible, encrypt your message with our PGP key; abeg download am from di Microsoft Security Response Center PGP Key page.
You suppose get response within 24 hours. If for any reason you no get, abeg follow up with email to make sure say we receive your first message. You fit find more info for microsoft.com/msrc.
Abeg include di information wey we list below (as much as you fit provide) to help us understand di nature and scope of di possible wahala:
- Di type of wahala (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
- Full paths of di source file(s) wey relate to di wahala
- Di location of di affected source code (tag/branch/commit or direct URL)
- Any special configuration wey you need to reproduce di wahala
- Step-by-step instructions to reproduce di wahala
- Proof-of-concept or exploit code (if e possible)
- Di impact of di wahala, including how attacker fit take exploit di wahala
Dis information go help us triage your report quick-quick.
If you dey report for bug bounty, di more complete your report be, di higher di bounty award fit be. Abeg visit our Microsoft Bug Bounty Program page to see more details about di programs wey dey active.
Preferred Languages
We go like make all communication dey for English.
Policy
Microsoft dey follow di principle of Coordinated Vulnerability Disclosure.
Disclaimer:
Dis dokyument don use AI translation service Co-op Translator take translate am. Even though we dey try make sure say e correct, abeg sabi say automatic translation fit get mistake or no dey accurate well. Di original dokyument for im native language na im you go take as di main correct one. For important information, e go better make professional human translator check am. We no go fit take blame for any misunderstanding or wrong interpretation wey fit happen because you use dis translation.