Skip to content
This repository was archived by the owner on Oct 13, 2025. It is now read-only.

Security: AvaloniaUI/Avalonia.Controls.TreeDataGrid

Security

SECURITY.md

Security Policy

This is the default security policy for AvaloniaUI repositories. Individual repositories may have their own SECURITY.md with product-specific details (supported versions, package scope) — if the repository you are reporting against has one, follow that instead.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, pull requests, or social media.

If you discover a security vulnerability in any of our SDKs, tools, services, or repositories, please report it privately so we can investigate and release a fix before public disclosure.

Reporting via GitHub

Where available, use GitHub's private vulnerability reporting on the affected repository: go to the repository's Security tab and choose Report a vulnerability. This creates a private security advisory where you can collaborate confidentially with the Avalonia team until a fix is available. GitHub's guide to the process is here: https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/privately-reporting-a-security-vulnerability

Reporting via Email

Alternatively, email security@avaloniaui.net.

What to include

Where possible, include:

  • A description of the vulnerability and its potential impact
  • The affected repository, package, component, or version ranges
  • Steps to reproduce, or a proof of concept
  • Whether you are aware of the issue being exploited in the wild
  • Any suggested mitigations
  • How you would like to be credited, or whether you prefer to stay anonymous

What to expect

  • We will acknowledge your report within 2 business days.
  • We will confirm whether we consider it a vulnerability and give you a remediation timeline within 10 business days.
  • We will keep you informed of progress and coordinate the disclosure date with you. Please allow us a reasonable period to release a fix or mitigation before disclosing publicly.
  • We will credit you in the published advisory unless you ask us not to.

Avalonia does not operate a bug bounty programme.

There aren't any published security advisories