Project governance should be updated to require that security vulnerabilities be [reported to secure@microsoft.com](https://technet.microsoft.com/en-us/security/ff852094.aspx) To allow [coordinated Vulnerability Disclosure](https://technet.microsoft.com/en-us/security/dn467923)