Update security reporting policy to recommend security portal for more streamlined reporting (#18437)

This commit is contained in:
Travis Plunk 2022-11-09 14:27:13 -08:00 committed by GitHub
parent 1ae9faddb8
commit fe76300a5f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

4
.github/SECURITY.md vendored
View File

@ -8,5 +8,5 @@ change, but PowerShell must be secure by default.
## Reporting a security vulnerability
If you believe that there is a security vulnerability in PowerShell,
it **must** be reported to [secure@microsoft.com](https://technet.microsoft.com/security/ff852094.aspx) to allow for [Coordinated Vulnerability Disclosure](https://technet.microsoft.com/security/dn467923).
**Only** file an issue, if [secure@microsoft.com](https://www.microsoft.com/en-us/msrc/faqs-report-an-issue?rtc=1) has confirmed filing an issue is appropriate.
it **must** be reported using [https://aka.ms/secure-at](https://aka.ms/secure-at) to allow for [Coordinated Vulnerability Disclosure](https://technet.microsoft.com/security/dn467923).
**Only** file an issue, if [MSRC](https://www.microsoft.com/en-us/msrc/faqs-report-an-issue?rtc=1) has confirmed filing an issue is appropriate.