generated: '2026-08-06' method: searched probe: true source: https://github.com/Azure/autorest/blob/main/SECURITY.md summary: >- AutoRest carries the standard Microsoft SECURITY.md (MSRC block v0.0.7) in its repository root. Vulnerabilities are reported to the Microsoft Security Response Center, not to the AutoRest maintainers, and the project inherits Microsoft's Coordinated Vulnerability Disclosure policy and bug bounty program. AutoRest publishes no /.well-known/security.txt of its own because it operates no domain — the project lives entirely on github.com. policy: - https://github.com/Azure/autorest/blob/main/SECURITY.md - https://aka.ms/opensource/security/cvd contact: - https://msrc.microsoft.com/create-report - secure@microsoft.com report_channels: - name: Microsoft Security Response Center (MSRC) url: https://msrc.microsoft.com/create-report preferred: true - name: Email value: secure@microsoft.com note: PGP key published at https://aka.ms/opensource/security/pgpkey bug_bounty: program: Microsoft Bug Bounty Program url: https://aka.ms/opensource/security/bounty covers_repo: true disclosure_policy: model: Coordinated Vulnerability Disclosure url: https://aka.ms/opensource/security/cvd vulnerability_definition: https://aka.ms/opensource/security/definition public_issues_prohibited: true response_commitment: acknowledgement: within 24 hours source: SECURITY.md preferred_languages: [English] requested_report_contents: - Type of issue (buffer overflow, SQL injection, cross-site scripting, ...) - Full paths of source files related to the manifestation of the issue - Location of the affected source code (tag/branch/commit or direct URL) - Any special configuration required to reproduce the issue - Step-by-step instructions to reproduce - Proof-of-concept or exploit code, if possible - Impact of the issue, including how an attacker might exploit it security_txt: published: false note: >- /.well-known/security.txt was not probed as an AutoRest asset — the only host serving this project is github.com, whose security.txt belongs to GitHub Inc., not to AutoRest. Recording it here would be false credit. evidence: - source: https://github.com/Azure/autorest/blob/main/SECURITY.md kind: security-policy http_status: 200 keywords: [msrc, coordinated vulnerability disclosure, bug bounty, secure@microsoft.com] x-evidence: fetched: '2026-08-06' sources: - url: https://raw.githubusercontent.com/Azure/autorest/main/SECURITY.md http_status: 200 - url: https://github.com/Azure/autorest/blob/main/SECURITY.md http_status: 200