Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: Adding Microsoft SECURITY.MD #122

Conversation

microsoft-github-policy-service[bot]
Copy link
Contributor

Please accept this contribution adding the standard Microsoft SECURITY.MD 🔒 file to help the community understand the security policy and how to safely report security issues. GitHub uses the presence of this file to light-up security reminders and a link to the file. This pull request commits the latest official SECURITY.MD file from https://github.com/microsoft/repo-templates/blob/main/shared/SECURITY.md.

Microsoft teams can learn more about this effort and share feedback within the open source guidance available internally.

Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary by GPT-4

This commit adds a SECURITY.md file to the repository, which outlines Microsoft's security policy and provides guidelines for reporting security vulnerabilities. The file emphasizes the importance of not reporting security vulnerabilities through public GitHub issues and instead directs users to report them to the Microsoft Security Response Center (MSRC) or via email. It also includes a list of requested information to help triage reports more quickly and mentions Microsoft's Bug Bounty Program for eligible reports. The policy follows the principle of Coordinated Vulnerability Disclosure.

Suggestions

No suggestions are needed as the PR is clear and well-structured.

@dciborow dciborow changed the title Adding Microsoft SECURITY.MD chore: Adding Microsoft SECURITY.MD Jun 5, 2023
@dciborow dciborow self-requested a review June 5, 2023 18:50
@dciborow dciborow merged commit d6814c9 into main Jun 5, 2023
@dciborow dciborow deleted the users/GitHubPolicyService/a9840cc0-d207-4857-8ab1-3dfcb232a8b0 branch June 5, 2023 18:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant