diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..8b20f7e --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,42 @@ +# Security Policy + +Microsoft takes the security of our software products and services seriously, which includes all source code repositories managed through our GitHub organizations. + +## Reporting Security Vulnerabilities + +**Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.** + +Instead, report them to the Microsoft Security Response Center (MSRC): + +- Report a vulnerability: https://msrc.microsoft.com/create-report +- MSRC vulnerability reporting guidance: https://www.microsoft.com/msrc + +If you prefer to submit without logging in, use: + +- https://www.microsoft.com/msrc/report-a-vulnerability + +You should receive a response within 24 hours. If you do not receive a response, please follow up via the reporting portal. + +Please include as much information as possible to help us reproduce and investigate the issue: + +- Type of issue +- Full paths of affected files or components +- Steps to reproduce +- Proof-of-concept code (if available) +- Potential impact assessment + +## Supported Versions + +As this project is under active development, security fixes are typically provided in the latest version of the repository. + +Users are encouraged to: +- Use the latest released version. +- Keep dependencies up to date. +- Follow Azure and Microsoft security best practices when deploying solutions based on this repository. + +## Additional Resources + +For more information about Microsoft's vulnerability disclosure process, see: + +- Microsoft Security Response Center: https://www.microsoft.com/msrc +- Coordinated Vulnerability Disclosure: https://www.microsoft.com/msrc/cvd