This is the default security policy for AvaloniaUI repositories. Individual repositories may have their own SECURITY.md with product-specific details (supported versions, package scope) — if the repository you are reporting against has one, follow that instead.
Please do not report security vulnerabilities through public GitHub issues, discussions, pull requests, or social media.
If you discover a security vulnerability in any of our SDKs, tools, services, or repositories, please report it privately so we can investigate and release a fix before public disclosure.
Where available, use GitHub's private vulnerability reporting on the affected repository: go to the repository's Security tab and choose Report a vulnerability. This creates a private security advisory where you can collaborate confidentially with the Avalonia team until a fix is available. GitHub's guide to the process is here: https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/privately-reporting-a-security-vulnerability
Alternatively, email security@avaloniaui.net.
Where possible, include:
- A description of the vulnerability and its potential impact
- The affected repository, package, component, or version ranges
- Steps to reproduce, or a proof of concept
- Whether you are aware of the issue being exploited in the wild
- Any suggested mitigations
- How you would like to be credited, or whether you prefer to stay anonymous
- We will acknowledge your report within 2 business days.
- We will confirm whether we consider it a vulnerability and give you a remediation timeline within 10 business days.
- We will keep you informed of progress and coordinate the disclosure date with you. Please allow us a reasonable period to release a fix or mitigation before disclosing publicly.
- We will credit you in the published advisory unless you ask us not to.
Avalonia does not operate a bug bounty programme.