3.4 KiB
Security
Microsoft dey take the security of our software products and services seriously, wey include all source code repositories wey dey managed through our GitHub organizations, wey include Microsoft, Azure, DotNet, AspNet, Xamarin, and our GitHub organizations.
If you believe say you don find security vulnerability for any Microsoft-owned repository wey meet Microsoft's definition of a security vulnerability, abeg report am to us as we describe below.
Reporting Security Issues
Abeg make you no report security vulnerabilities through public GitHub issues.
Instead, abeg report dem to the Microsoft Security Response Center (MSRC) for https://msrc.microsoft.com/create-report.
If you prefer to submit without logging in, send email go secure@microsoft.com. If e possible, encrypt your message with our PGP key; abeg download am from the Microsoft Security Response Center PGP Key page.
You go get response inside 24 hours. If for any reason you no get am, abeg follow up through email make sure say we receive your original message. You fit find more information for microsoft.com/msrc.
Abeg include the requested information wey dey below (as much as you fit give) to help us better understand the nature and scope of the possible issue:
- Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
- Full paths of the source file(s) wey relate to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration wey dey required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if e possible)
- Impact of the issue, including how attacker fit exploit the issue
This information go help us triage your report faster.
If you dey report for bug bounty, more complete reports fit make you get higher bounty award. Abeg visit our Microsoft Bug Bounty Program page make you see more details about our active programs.
Preferred Languages
We prefer say all communications go dey English.
Policy
Microsoft dey follow the principle of Coordinated Vulnerability Disclosure.
Disclaimer: Dis document don translate using AI translation service wey dem dey call Co-op Translator. Even though we try make am correct, abeg sabi say automated translation fit get some mistakes or wahala. Di original document wey original language n be di correct one. If na serious matter, better make professional human translation do am. We no go hold ourselves responsible if pesin for misunderstand or mix up tins because of dis translation.