aspnet / AspNetWebStack

ASP.NET MVC 5.x, Web API 2.x, and Web Pages 3.x (not ASP.NET Core)
Other
858 stars 354 forks source link

Add SECURITY.md #425

Closed terrajobst closed 2 months ago

CZEMacLeod commented 2 months ago

Since this project (and katana) are not aspnetcore or netcore - I think you might need to reword the first part.

terrajobst commented 2 months ago

@blowdart I assume the spirit applies here as well. Do we have wording for non-core bits?

blowdart commented 2 months ago

Security Policy

Reporting a Vulnerability

Security issues and bugs should be reported privately to the Microsoft Security Response Center (MSRC), either by emailing secure@microsoft.com or via the portal at https://msrc.microsoft.com. You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message. Further information, including the MSRC PGP key, can be found in the MSRC Report an Issue FAQ.

Please do not open issues for anything you think might have a security implication.

terrajobst commented 2 months ago

Fixed