Do not report exploitable vulnerabilities or credentials in public issues.
Use GitHub private vulnerability reporting if enabled. Otherwise contact the repository owner privately before sharing sensitive details.
Report vulnerabilities in Microsoft Azure services or upstream Microsoft components through their own published security channels.
The foundation requires live identity, authorization, networking, and recovery validation before production use. See operations and release checks.