Skip to content

Latest commit

 

History

History
44 lines (29 loc) · 1.12 KB

File metadata and controls

44 lines (29 loc) · 1.12 KB

Security Policy

Supported Versions

We provide security updates for the main branch and the latest release line. Older versions may not receive patches.

Version Supported
main Yes
Latest release Yes
Older releases No

Reporting a Vulnerability

Please do not open public GitHub issues for security vulnerabilities.

To report a vulnerability, email:

  • bo.li@microsoft.com

Include the following details when possible:

  1. A clear description of the issue and potential impact.
  2. Steps to reproduce (or a proof of concept).
  3. Affected versions, branches, and files.
  4. Any suggested mitigation.

Response Process

We will:

  1. Acknowledge receipt within 5 business days.
  2. Validate and triage the report.
  3. Work on a fix and coordinate disclosure timing.
  4. Credit the reporter when appropriate and requested.

Disclosure Policy

We follow responsible disclosure:

  • Keep reports private until a fix or mitigation is available.
  • Coordinate release notes with severity and affected scope.
  • Encourage reporters to avoid publishing exploit details before patch release.