diff --git a/.github/workflows/managed-build.yml b/.github/workflows/managed-build.yml index fe30268d..e3ffd3b8 100644 --- a/.github/workflows/managed-build.yml +++ b/.github/workflows/managed-build.yml @@ -11,9 +11,9 @@ jobs: runs-on: windows-latest steps: - uses: actions/checkout@v2 - - uses: nuget/setup-nuget@v1.0.2 + - uses: nuget/setup-nuget@v1.0.6 - name: Restore run: nuget restore src/BehaviorsSDKManaged/BehaviorsSDKManaged.sln - - uses: microsoft/setup-msbuild@v1.0.1 + - uses: microsoft/setup-msbuild@v1.0.2 - name: Build run: msbuild src/BehaviorsSDKManaged/BehaviorsSDKManaged.sln /p:Configuration=Release diff --git a/.github/workflows/native-build.yml b/.github/workflows/native-build.yml index f6a51da9..d306e205 100644 --- a/.github/workflows/native-build.yml +++ b/.github/workflows/native-build.yml @@ -11,9 +11,9 @@ jobs: runs-on: windows-latest steps: - uses: actions/checkout@v2 - - uses: nuget/setup-nuget@v1.0.2 + - uses: nuget/setup-nuget@v1.0.6 - name: Restore run: nuget restore src/BehaviorsSDKNative/BehaviorsSDKNative.sln - - uses: microsoft/setup-msbuild@v1.0.1 + - uses: microsoft/setup-msbuild@v1.0.2 - name: Build - run: msbuild src/BehaviorsSDKNative/BehaviorsSDKNative.sln /p:Configuration=Release \ No newline at end of file + run: msbuild src/BehaviorsSDKNative/BehaviorsSDKNative.sln /p:Configuration=Release diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..869fdfe2 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,41 @@ + + +## Security + +Microsoft takes the security of our software products and services seriously, which includes all source code repositories managed through our GitHub organizations, which include [Microsoft](https://github.com/Microsoft), [Azure](https://github.com/Azure), [DotNet](https://github.com/dotnet), [AspNet](https://github.com/aspnet), [Xamarin](https://github.com/xamarin), and [our GitHub organizations](https://opensource.microsoft.com/). + +If you believe you have found a security vulnerability in any Microsoft-owned repository that meets [Microsoft's definition of a security vulnerability](https://aka.ms/opensource/security/definition), please report it to us as described below. + +## Reporting Security Issues + +**Please do not report security vulnerabilities through public GitHub issues.** + +Instead, please report them to the Microsoft Security Response Center (MSRC) at [https://msrc.microsoft.com/create-report](https://aka.ms/opensource/security/create-report). + +If you prefer to submit without logging in, send email to [secure@microsoft.com](mailto:secure@microsoft.com). If possible, encrypt your message with our PGP key; please download it from the [Microsoft Security Response Center PGP Key page](https://aka.ms/opensource/security/pgpkey). + +You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message. Additional information can be found at [microsoft.com/msrc](https://aka.ms/opensource/security/msrc). + +Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue: + + * Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.) + * Full paths of source file(s) related to the manifestation of the issue + * The location of the affected source code (tag/branch/commit or direct URL) + * Any special configuration required to reproduce the issue + * Step-by-step instructions to reproduce the issue + * Proof-of-concept or exploit code (if possible) + * Impact of the issue, including how an attacker might exploit the issue + +This information will help us triage your report more quickly. + +If you are reporting for a bug bounty, more complete reports can contribute to a higher bounty award. Please visit our [Microsoft Bug Bounty Program](https://aka.ms/opensource/security/bounty) page for more details about our active programs. + +## Preferred Languages + +We prefer all communications to be in English. + +## Policy + +Microsoft follows the principle of [Coordinated Vulnerability Disclosure](https://aka.ms/opensource/security/cvd). + + diff --git a/src/BehaviorsSDKManaged/Microsoft.Xaml.Interactions.Design/Microsoft.Xaml.Interactions.Design.csproj b/src/BehaviorsSDKManaged/Microsoft.Xaml.Interactions.Design/Microsoft.Xaml.Interactions.Design.csproj index 01b7e453..4d344d04 100644 --- a/src/BehaviorsSDKManaged/Microsoft.Xaml.Interactions.Design/Microsoft.Xaml.Interactions.Design.csproj +++ b/src/BehaviorsSDKManaged/Microsoft.Xaml.Interactions.Design/Microsoft.Xaml.Interactions.Design.csproj @@ -10,7 +10,7 @@ Properties Microsoft.Xaml.Interactions.Design Microsoft.Xaml.Interactions.Design - v4.5.1 + v4.7.2 512 {60dc8134-eba5-43b8-bcc9-bb4bc16c2548};{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} 4 diff --git a/src/BehaviorsSDKManaged/Microsoft.Xaml.Interactivity.Design/Microsoft.Xaml.Interactivity.Design.csproj b/src/BehaviorsSDKManaged/Microsoft.Xaml.Interactivity.Design/Microsoft.Xaml.Interactivity.Design.csproj index 15147ceb..8edccba4 100644 --- a/src/BehaviorsSDKManaged/Microsoft.Xaml.Interactivity.Design/Microsoft.Xaml.Interactivity.Design.csproj +++ b/src/BehaviorsSDKManaged/Microsoft.Xaml.Interactivity.Design/Microsoft.Xaml.Interactivity.Design.csproj @@ -10,7 +10,7 @@ Properties Microsoft.Xaml.Interactivity.Design Microsoft.Xaml.Interactivity.Design - v4.5.1 + v4.7.2 512 {60dc8134-eba5-43b8-bcc9-bb4bc16c2548};{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} 4 diff --git a/src/BehaviorsSDKNative/Microsoft.Xaml.Interactions.Design/Microsoft.Xaml.Interactions.Design.csproj b/src/BehaviorsSDKNative/Microsoft.Xaml.Interactions.Design/Microsoft.Xaml.Interactions.Design.csproj index c501feb2..60178212 100644 --- a/src/BehaviorsSDKNative/Microsoft.Xaml.Interactions.Design/Microsoft.Xaml.Interactions.Design.csproj +++ b/src/BehaviorsSDKNative/Microsoft.Xaml.Interactions.Design/Microsoft.Xaml.Interactions.Design.csproj @@ -9,7 +9,7 @@ Properties Microsoft.Xaml.Interactions.Design Microsoft.Xaml.Interactions.Design - v4.5.1 + v4.7.2 512 {60dc8134-eba5-43b8-bcc9-bb4bc16c2548};{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} 4 diff --git a/src/BehaviorsSDKNative/Microsoft.Xaml.Interactivity.Design/Microsoft.Xaml.Interactivity.Design.csproj b/src/BehaviorsSDKNative/Microsoft.Xaml.Interactivity.Design/Microsoft.Xaml.Interactivity.Design.csproj index cecb6576..15cea713 100644 --- a/src/BehaviorsSDKNative/Microsoft.Xaml.Interactivity.Design/Microsoft.Xaml.Interactivity.Design.csproj +++ b/src/BehaviorsSDKNative/Microsoft.Xaml.Interactivity.Design/Microsoft.Xaml.Interactivity.Design.csproj @@ -9,7 +9,7 @@ Properties Microsoft.Xaml.Interactivity.Design Microsoft.Xaml.Interactivity.Design - v4.5.1 + v4.7.2 512 {60dc8134-eba5-43b8-bcc9-bb4bc16c2548};{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC} 4