Skip to content
This repository was archived by the owner on Feb 14, 2025. It is now read-only.

Security: wixtoolset/VisualStudioExtension

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report suspected security vulnerabilities in the WiX Toolset privately by email to [security@firegiant.com] (mailto:security@firegiant.com).

Please do not open a public GitHub issue, discussion, or pull request, or disclose the issue publicly, until FireGiant has had an opportunity to assess and coordinate the report.

When available, please include:

  • the affected WiX version, package, build, commit, or component;
  • a description of the vulnerability and potential impact;
  • prerequisites and a realistic attack scenario;
  • reproduction steps or proof-of-concept material;
  • information about known exploitation or planned disclosure; and
  • a way for us to contact you.

Incomplete reports are welcome. Please do not include unnecessary personal data. If you need to send sensitive attachments or proof-of-concept material, contact us first so we can arrange a secure transfer method.

What happens next

FireGiant will acknowledge and assess reports, coordinate with the reporter and affected maintainers where appropriate, and work toward a fix or mitigation.

The public FireGiant product security and coordinated disclosure process is available at https://www.firegiant.com/security/.

Supported versions

Security fixes are evaluated for currently supported WiX releases. Issues affecting older releases may also be assessed based on severity, reach, and practical remediation options.

For ordinary bugs and feature requests, please use the public WiX issue tracker.

There aren't any published security advisories