Microsoft takes the security of our software products and services seriously, including source code repositories managed through our GitHub organizations.
Please do not report security vulnerabilities through public GitHub issues.
For security reporting information, locations, contact information, and policies, review the latest guidance for Microsoft repositories at https://aka.ms/SECURITY.md.
When reporting a potential vulnerability, include as much detail as possible:
- Type of issue, such as authentication bypass, SQL injection, cross-site scripting, secret exposure, or unsafe deployment default
- Affected file paths, branch, tag, or commit
- Steps to reproduce and any required configuration
- Impact and any proof-of-concept details
Microsoft follows Coordinated Vulnerability Disclosure.