Skip to content

Security: dotnet/aspnetcore

Security

SECURITY.md

Security Policy

Supported Versions

The .NET Core and ASP.NET Core support policy, including supported versions can be found at the .NET Core Support Policy Page.

Reporting a Vulnerability

Security issues and bugs should be reported privately, via email, to the Microsoft Security Response Center (MSRC) through https://msrc.microsoft.com or by emailing secure@microsoft.com. You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message. Further information, including the MSRC PGP key, can be found in the MSRC Report an Issue FAQ.

Reports via MSRC may qualify for the .NET Core Bug Bounty. Details of the .NET Core Bug Bounty including terms and conditions are at https://aka.ms/corebounty.

Please do not open issues for anything you think might have a security implication.

Learn more about advisories related to dotnet/aspnetcore in the GitHub Advisory Database