Skip to content

Security: jarrodkrige/agentpublishsample

Security

SECURITY.md

Security policy

Supported scope

This repository is a reference sample rather than a hosted service. Security fixes are applied to the latest version of the default branch. Consumers are responsible for their deployed copies, identities, customer onboarding policy and operational controls.

Reporting a vulnerability

Do not disclose a suspected vulnerability in a public issue, discussion, pull request, log or Microsoft 365 app package. Use the repository's private vulnerability reporting facility to provide:

  • the affected file and version;
  • reproduction steps or a minimal proof of concept;
  • the expected security impact;
  • any known mitigation.

If private vulnerability reporting is unavailable, contact the repository maintainers through an established private channel before sharing technical details.

Never include live credentials, tokens, tenant identifiers, customer data or private telemetry in a report. Replace them with synthetic values.

Deployment responsibility

Before production use, review identity, tenant isolation, least-privilege roles, network exposure, telemetry retention, content safety, privacy, support and incident response requirements. The sample's Microsoft Learn MCP integration is demonstration grounding and does not approve another MCP service for production use.

There aren't any published security advisories