Skip to content

Commit d9bd295

Browse files
authored
Repo File Sync: Add SECURITY.md file (#193)
synced local file(s) with [microsoft/mu_devops](https://github.com/microsoft/mu_devops). 🤖: View the [Repo File Sync Configuration File](https://github.com/microsoft/mu_devops/blob/main/.sync/Files.yml) to see how files are synced. --- This PR was created automatically by the [repo-file-sync-action](https://github.com/BetaHuhn/repo-file-sync-action) workflow run [#5153770086](https://github.com/microsoft/mu_devops/actions/runs/5153770086) Signed-off-by: Project Mu UEFI Bot <uefibot@microsoft.com>
1 parent 0dca82a commit d9bd295

1 file changed

Lines changed: 39 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
# Project Mu Security Policy
2+
3+
Project Mu is an open source firmware project that is leveraged by and combined into
4+
other projects to build the firmware for a given product. We build and maintain this
5+
code with the intent that any consuming projects can use this code as-is. If features
6+
or fixes are necessary we ask that they contribute them back to the project. **But**, that
7+
said, in the firmware ecosystem there is a lot of variation and differentiation, and
8+
the license in this project allows flexibility for use without contribution back to
9+
Project Mu. Therefore, any issues found here may or may not exist in products using Project Mu.
10+
11+
## Supported Versions
12+
13+
Due to the usage model we generally only supply fixes to the most recent release branch (or main).
14+
For a serious vulnerability we may patch older release branches.
15+
16+
## Additional Notes
17+
18+
Project Mu contains code that is available and/or originally authored in other
19+
repositories (see <https://github.com/tianocore/edk2> as one such example). For any
20+
vulnerability found, we may be subject to their security policy and may need to work
21+
with those groups to resolve amicably and patch the "upstream". This might involve
22+
additional time to release and/or additional confidentiality requirements.
23+
24+
## Reporting a Vulnerability
25+
26+
**Please do not report security vulnerabilities through public GitHub issues.**
27+
28+
Instead please use **Github Private vulnerability reporting**, which is enabled for each Project Mu
29+
repository. This process is well documented by github in their documentation [here](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability#privately-reporting-a-security-vulnerability).
30+
31+
This process will allow us to privately discuss the issue, collaborate on a solution, and then disclose the vulnerability.
32+
33+
## Preferred Languages
34+
35+
We prefer all communications to be in English.
36+
37+
## Policy
38+
39+
Microsoft follows the principle of [Coordinated Vulnerability Disclosure](https://www.microsoft.com/en-us/msrc/cvd).

0 commit comments

Comments
 (0)