Skip to content

Commit

Permalink
Update SECURITY.md
Browse files Browse the repository at this point in the history
  • Loading branch information
wickste authored Feb 7, 2024
1 parent 37ff82f commit 4fbf208
Showing 1 changed file with 12 additions and 27 deletions.
39 changes: 12 additions & 27 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,35 +1,20 @@
## Security
# Security Policy

Microsoft takes the security of our software products and services seriously, which includes all source code repositories managed through our GitHub organizations, which include [Microsoft](/~https://github.com/Microsoft), [Azure](/~https://github.com/Azure), [DotNet](/~https://github.com/dotnet), [AspNet](/~https://github.com/aspnet), [Xamarin](/~https://github.com/xamarin), and [our GitHub organizations](https://opensource.microsoft.com/).
## Supported Versions

If you believe you have found a security vulnerability in any Microsoft-owned repository that meets Microsoft's [Microsoft's definition of a security vulnerability](https://docs.microsoft.com/previous-versions/tn-archive/cc751383(v=technet.10)), please report it to us as described below.
| Version | Supported |
| ------- | ------------------ |
| 6.4.x | :white_check_mark: |

## Reporting Security Issues
## Reporting a Vulnerability

**Please do not report security vulnerabilities through public GitHub issues.**
If you think you have found a vulnerability in <project> you can report it using one of the following ways:

Instead, please report them to the Microsoft Security Response Center (MSRC) at [https://msrc.microsoft.com/create-report](https://msrc.microsoft.com/create-report).
* Contact the [Eclipse Foundation Security Team](mailto:security@eclipse-foundation.org)
* [Report a Vulnerability](/~https://github.com/eclipse-threadx/getting-started/security/advisories/new)

If you prefer to submit without logging in, send email to [secure@microsoft.com](mailto:secure@microsoft.com). If possible, encrypt your message with our PGP key; please download it from the the [Microsoft Security Response Center PGP Key page](https://www.microsoft.com/msrc/pgp-key-msrc).
You can find more information about reporting and disclosure at the [Eclipse Foundation Security page](https://www.eclipse.org/security/).

You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message. Additional information can be found at [microsoft.com/msrc](https://www.microsoft.com/msrc).
## Security Policy

Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:

* Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
* Full paths of source file(s) related to the manifestation of the issue
* The location of the affected source code (tag/branch/commit or direct URL)
* Any special configuration required to reproduce the issue
* Step-by-step instructions to reproduce the issue
* Proof-of-concept or exploit code (if possible)
* Impact of the issue, including how an attacker might exploit the issue

This information will help us triage your report more quickly.

## Preferred Languages

We prefer all communications to be in English.

## Policy

Microsoft follows the principle of [Coordinated Vulnerability Disclosure](https://www.microsoft.com/msrc/cvd).
This project follows [Eclipse Foundation Vulnerability Reporting Policy](https://www.eclipse.org/security/policy/).

0 comments on commit 4fbf208

Please sign in to comment.