chore: add SECURITY.md and broken API issue template

- SECURITY.md documents endpoint stability per area, how to report
  broken Graph endpoints, and links to the MS Graph changelog
- New issue template for broken API reports with structured fields
  (page, error, date, endpoint, license tier)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Samir Khan
2026-06-18 17:07:45 +05:30
co-authored by Claude Sonnet 4.6
parent 748f7ccb29
commit 5a7dd86a3b
2 changed files with 74 additions and 15 deletions
+28
View File
@@ -0,0 +1,28 @@
---
name: Broken API Endpoint
about: A dashboard card stopped working due to a Microsoft Graph API change
title: '[BROKEN API] '
labels: broken-api
assignees: ''
---
**Which page and card is affected?**
e.g. Identity page → Risk Detections card
**What error is shown on screen?**
e.g. 403 Forbidden / 404 Not Found / blank card
**When did it stop working?**
Approximate date:
**Graph endpoint involved (if known):**
e.g. `/v1.0/identityProtection/riskDetections`
**Link to Microsoft changelog (if you found it):**
https://developer.microsoft.com/en-us/graph/changelog
**Your tenant license (helps narrow down the issue):**
- [ ] Microsoft 365 Business Premium
- [ ] Microsoft 365 E3
- [ ] Microsoft 365 E5
- [ ] Other:
+46 -15
View File
@@ -1,21 +1,52 @@
# Security Policy
# Security & API Status
## Supported Versions
## Reporting a Security Vulnerability
Use this section to tell people about which versions of your project are
currently being supported with security updates.
If you find a security issue (e.g. credentials being logged, an endpoint leaking data), please **do not open a public issue**. Open a [GitHub Security Advisory](https://github.com/sameerk27/vigil365/security/advisories/new) instead so it can be fixed before public disclosure.
| Version | Supported |
| ------- | ------------------ |
| 5.1.x | :white_check_mark: |
| 5.0.x | :x: |
| 4.0.x | :white_check_mark: |
| < 4.0 | :x: |
---
## Reporting a Vulnerability
## Reporting a Broken Graph API Endpoint
Use this section to tell people how to report a vulnerability.
Microsoft occasionally changes, deprecates, or moves Graph API endpoints. If a dashboard card stops working or shows a permission error, please open an issue using this format:
Tell them where to go, how often they can expect to get an update on a
reported vulnerability, what to expect if the vulnerability is accepted or
declined, etc.
**Title:** `[BROKEN API] <page name> — <endpoint>`
**Include:**
- Which page/card is affected (e.g. "Identity page — Risk Detections card")
- The error shown on screen (e.g. "403 Forbidden" or "404 Not Found")
- Your approximate date when it broke
- Link to the Microsoft changelog entry if you found one
---
## Known API Stability
| Endpoint area | Stability | Notes |
|--------------|-----------|-------|
| Risky users / sign-ins | ✅ Stable | v1.0, unchanged since 2021 |
| MFA registration details | ✅ Stable | v1.0 |
| Intune device compliance | ✅ Stable | v1.0 |
| Conditional Access policies | ✅ Stable | v1.0 |
| Defender XDR alerts (`alerts_v2`) | ✅ Stable | v1.0, replaced `alerts` in 2022 |
| Defender XDR incidents | ✅ Stable | v1.0 |
| Service health | ✅ Stable | v1.0 |
| Audit logs / sign-ins | ✅ Stable | v1.0 |
| Attack simulation | ⚠️ Watch | v1.0 but feature-flagged by license |
| Insider Risk (IRM) | ⚠️ Watch | Requires Microsoft Purview license |
| Identity health issues | ⚠️ Beta | `/beta/` endpoint — may change without notice |
| MCAS alerts | ⚠️ Watch | Merging into Defender XDR over time |
---
## Staying Ahead of Changes
Subscribe to the official Microsoft Graph changelog to get notified of breaking changes:
🔗 [https://developer.microsoft.com/en-us/graph/changelog](https://developer.microsoft.com/en-us/graph/changelog)
---
## How the App Handles Broken Endpoints
Each dashboard card fetches independently. If one Graph endpoint returns an error (403, 404, 429), that card shows an inline error message — **all other pages and cards keep working**. No single API change can break the whole dashboard.