Sitelet https://github.com/microsoft/nacelle/security
Skip to content

Security: microsoft/nacelle

SECURITY.md

Security

Microsoft takes the security of our software products and services seriously, which includes all source code repositories in our GitHub organizations.

Please do not report security vulnerabilities through public GitHub issues.

For security reporting information, locations, contact information, and policies, please review the latest guidance for Microsoft repositories at https://aka.ms/SECURITY.md.

Transport Security

Configure proxy identity, body budgets, and HTTP error handling as described in the HTTP hardening reference. Applications own authentication, authorization, and any diagnostics exposed to clients.

Rustls builds require 0.23.45 or newer, which addresses RUSTSEC-2026-0285. The OpenSSL PEM helper requires TLS 1.2 or newer; custom TLS configurations own their policy. See runtime limits for certificate reload and memory-accounting guarantees and limitations.

There aren't any published security advisories