AutoRest · Vulnerability Disclosure

Autorest Vulnerability Disclosure

Vulnerability disclosure

AutoRest publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

Code GenerationMicrosoftOpenAPISDK GenerationAzure SDKDeprecated
Program:

Disclosure Policy

Policy
Policy

Security Contact

Contact
https://msrc.microsoft.com/create-report
Contact
secure@microsoft.com

Source

Vulnerability Disclosure

autorest-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-06'
method: searched
probe: true
source: https://github.com/Azure/autorest/blob/main/SECURITY.md
summary: >-
  AutoRest carries the standard Microsoft SECURITY.md (MSRC block v0.0.7) in its
  repository root. Vulnerabilities are reported to the Microsoft Security
  Response Center, not to the AutoRest maintainers, and the project inherits
  Microsoft's Coordinated Vulnerability Disclosure policy and bug bounty
  program. AutoRest publishes no /.well-known/security.txt of its own because it
  operates no domain — the project lives entirely on github.com.
policy:
  - https://github.com/Azure/autorest/blob/main/SECURITY.md
  - https://aka.ms/opensource/security/cvd
contact:
  - https://msrc.microsoft.com/create-report
  - secure@microsoft.com
report_channels:
  - name: Microsoft Security Response Center (MSRC)
    url: https://msrc.microsoft.com/create-report
    preferred: true
  - name: Email
    value: secure@microsoft.com
    note: PGP key published at https://aka.ms/opensource/security/pgpkey
bug_bounty:
  program: Microsoft Bug Bounty Program
  url: https://aka.ms/opensource/security/bounty
  covers_repo: true
disclosure_policy:
  model: Coordinated Vulnerability Disclosure
  url: https://aka.ms/opensource/security/cvd
  vulnerability_definition: https://aka.ms/opensource/security/definition
  public_issues_prohibited: true
response_commitment:
  acknowledgement: within 24 hours
  source: SECURITY.md
preferred_languages: [English]
requested_report_contents:
  - Type of issue (buffer overflow, SQL injection, cross-site scripting, ...)
  - Full paths of source files related to the manifestation of the issue
  - Location of the affected source code (tag/branch/commit or direct URL)
  - Any special configuration required to reproduce the issue
  - Step-by-step instructions to reproduce
  - Proof-of-concept or exploit code, if possible
  - Impact of the issue, including how an attacker might exploit it
security_txt:
  published: false
  note: >-
    /.well-known/security.txt was not probed as an AutoRest asset — the only
    host serving this project is github.com, whose security.txt belongs to
    GitHub Inc., not to AutoRest. Recording it here would be false credit.
evidence:
  - source: https://github.com/Azure/autorest/blob/main/SECURITY.md
    kind: security-policy
    http_status: 200
    keywords: [msrc, coordinated vulnerability disclosure, bug bounty, secure@microsoft.com]
x-evidence:
  fetched: '2026-08-06'
  sources:
    - url: https://raw.githubusercontent.com/Azure/autorest/main/SECURITY.md
      http_status: 200
    - url: https://github.com/Azure/autorest/blob/main/SECURITY.md
      http_status: 200