3.2 KiB
Security
Microsoft dey take di security of dia software products and services serious, e include all di source code repositories wey dem dey manage for dia GitHub organizations, wey include Microsoft, Azure, DotNet, AspNet, Xamarin, and our GitHub organizations.
If you feel say you don find security wahala for any Microsoft-owned repository wey match Microsoft's definition of a security vulnerability, abeg report am to us as we describe below.
How to Report Security Wahala
Abeg no report security wahala through public GitHub issues.
Instead, abeg report am to di Microsoft Security Response Center (MSRC) for https://msrc.microsoft.com/create-report.
If you wan submit am without logging in, send email go secure@microsoft.com. If e possible, encrypt your message with our PGP key; abeg download am from di Microsoft Security Response Center PGP Key page.
You suppose get response within 24 hours. If for any reason you no get response, abeg follow up with email to make sure say we receive your original message. You fit find more information for microsoft.com/msrc.
Abeg include di information wey we request below (as much as you fit provide) to help us understand di nature and scope of di wahala:
- Di type of wahala (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
- Full paths of di source file(s) wey relate to di wahala
- Di location of di affected source code (tag/branch/commit or direct URL)
- Any special configuration wey you need to reproduce di wahala
- Step-by-step instructions to reproduce di wahala
- Proof-of-concept or exploit code (if e possible)
- Di impact of di wahala, including how attacker fit use am
Dis information go help us triage your report quick.
If you dey report for bug bounty, di more complete your report be, di higher di bounty award fit be. Abeg visit our Microsoft Bug Bounty Program page for more details about di programs wey dey active.
Preferred Languages
We go like make all communication dey for English.
Policy
Microsoft dey follow di principle of Coordinated Vulnerability Disclosure.
Disclaimer:
Dis document don use AI translation service Co-op Translator take translate am. Even though we dey try make sure say e correct, abeg no forget say automated translations fit get mistake or no dey accurate well. Di original document for di language wey dem write am first na di main correct source. For important information, e better make una use professional human translation. We no go fit take responsibility for any misunderstanding or wrong interpretation wey fit happen because of dis translation.