You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
ML-For-Beginners/translations/en/SECURITY.md

3.4 KiB

Security

Microsoft prioritizes the security of its software products and services, including all source code repositories managed through our GitHub organizations, such as Microsoft, Azure, DotNet, AspNet, Xamarin, and our GitHub organizations.

If you believe you have identified a security vulnerability in any Microsoft-owned repository that aligns with Microsoft's definition of a security vulnerability, please report it to us using the process outlined below.

Reporting Security Issues

Do not report security vulnerabilities through public GitHub issues.

Instead, report them to the Microsoft Security Response Center (MSRC) at https://msrc.microsoft.com/create-report.

If you prefer to submit your report without logging in, you can email secure@microsoft.com. If possible, encrypt your message using our PGP key, which can be downloaded from the Microsoft Security Response Center PGP Key page.

You should receive a response within 24 hours. If you do not, please follow up via email to confirm that we received your original message. Additional details can be found at microsoft.com/msrc.

Please include the following information (as much as you can provide) to help us better understand the nature and scope of the potential issue:

  • Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of the source file(s) related to the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration needed to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if available)
  • Impact of the issue, including how an attacker might exploit it

Providing this information will help us process your report more efficiently.

If you are submitting a report for a bug bounty, more detailed reports may result in a higher bounty award. For more information about our active programs, visit the Microsoft Bug Bounty Program page.

Preferred Languages

We prefer all communications to be in English.

Policy

Microsoft adheres to the principles of Coordinated Vulnerability Disclosure.


Disclaimer:
This document has been translated using the AI translation service Co-op Translator. While we strive for accuracy, please note that automated translations may contain errors or inaccuracies. The original document in its native language should be regarded as the authoritative source. For critical information, professional human translation is recommended. We are not responsible for any misunderstandings or misinterpretations resulting from the use of this translation.