Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,17 @@ Microsoft follows the principle of [Coordinated Vulnerability Disclosure](https:

<!-- END MICROSOFT SECURITY.MD BLOCK -->

## Vulnerability Remediation

The project maintainers commit to remediating confirmed vulnerabilities based on severity:

| Severity | Remediation Target |
|-------------------|--------------------|
| Critical and High | 60 days |
| Medium | 90 days |

Remediation timelines begin when the vulnerability is confirmed and may involve a code fix, configuration change, dependency update, or documented mitigation. Tracking is done through GitHub Security Advisories or GitHub issues. If a fix requires more time, the maintainers will publish a mitigation or workaround within the target window and document the extended timeline.

## Security Considerations for Deployers

> [!IMPORTANT]
Expand Down
Loading