Security reports are taken seriously.
See the version-specific code-signing inventory for verified Windows releases, publisher details and verification instructions. Code signing establishes identity and integrity; it does not replace security testing or guarantee the absence of vulnerabilities.
Please do not disclose a suspected vulnerability in a public issue, discussion, pull request, or social post.
Use the repository's Security tab and select Report a vulnerability when private vulnerability reporting is available. Include:
- the affected repository, version, and component;
- clear reproduction steps or a minimal proof of concept;
- the expected and observed impact;
- relevant platform and environment details;
- any suggested mitigation, if known.
Reports will be reviewed as soon as practical. Please allow reasonable time for investigation and remediation before public disclosure. Do not access data that does not belong to you, disrupt services, or perform testing outside systems you own or are explicitly authorized to assess.
Unless a repository states otherwise, only the latest published release is actively supported with security fixes.