Skip to content

Conversation

@sirredbeard
Copy link
Contributor

MSRC no longer directly accepts e-mail submissions via [email protected]. Submissions must be reported via the MSRC portal or a one-time token for e-mail submission obtained from the MSRC portal.

This proposal updates the README.md and SECURITY.md to reflect these changes.

Copilot AI review requested due to automatic review settings November 3, 2025 15:56
@github-actions github-actions bot added the needs-area-label An area label is needed to ensure this gets routed to the appropriate area owners label Nov 3, 2025
@dotnet-policy-service dotnet-policy-service bot added the community-contribution Indicates that the PR has been added by a community member label Nov 3, 2025
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the security vulnerability reporting instructions in both SECURITY.md and README.md files. The changes modernize the reporting process by directing users to the MSRC Researcher Portal instead of email, and streamline the documentation by removing references to the now-obsolete PGP key.

Key changes:

  • Replaces email-based reporting ([email protected]) with a direct link to the MSRC Researcher Portal
  • Removes outdated references to the MSRC PGP key from both files
  • Maintains consistency in security reporting guidance across documentation

Reviewed Changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
SECURITY.md Updates vulnerability reporting method to use MSRC Researcher Portal and removes PGP key reference
README.md Aligns security reporting instructions with SECURITY.md changes, replacing email with portal link

@sirredbeard
Copy link
Contributor Author

@dotnet-policy-service agree company="HeroDevs, LLC"

@huoyaoyuan huoyaoyuan added area-Meta and removed needs-area-label An area label is needed to ensure this gets routed to the appropriate area owners labels Nov 3, 2025
@huoyaoyuan
Copy link
Member

Thank you for noticing this, but it's a template for all .NET Foundation repositories. The infra team should be responsible to apply the change for the whole organization.

@dotnet-policy-service
Copy link
Contributor

Tagging subscribers to this area: @dotnet/area-meta
See info in area-owners.md if you want to be subscribed.

@jkotas jkotas requested a review from blowdart November 3, 2025 16:49
@akoeplinger
Copy link
Member

/ba-g markdown changes only

@akoeplinger
Copy link
Member

@huoyaoyuan there's going to be a central process for updating the file, but it will take some time. We can take this change in the meantime

@akoeplinger akoeplinger merged commit 3083294 into dotnet:main Nov 3, 2025
25 of 26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-Meta community-contribution Indicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants