diff --git a/.github/ISSUE_TEMPLATE/broken_api.md b/.github/ISSUE_TEMPLATE/broken_api.md new file mode 100644 index 0000000..ef71991 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/broken_api.md @@ -0,0 +1,28 @@ +--- +name: Broken API Endpoint +about: A dashboard card stopped working due to a Microsoft Graph API change +title: '[BROKEN API] ' +labels: broken-api +assignees: '' +--- + +**Which page and card is affected?** +e.g. Identity page → Risk Detections card + +**What error is shown on screen?** +e.g. 403 Forbidden / 404 Not Found / blank card + +**When did it stop working?** +Approximate date: + +**Graph endpoint involved (if known):** +e.g. `/v1.0/identityProtection/riskDetections` + +**Link to Microsoft changelog (if you found it):** +https://developer.microsoft.com/en-us/graph/changelog + +**Your tenant license (helps narrow down the issue):** +- [ ] Microsoft 365 Business Premium +- [ ] Microsoft 365 E3 +- [ ] Microsoft 365 E5 +- [ ] Other: diff --git a/SECURITY.md b/SECURITY.md index 034e848..aac6184 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,21 +1,52 @@ -# Security Policy +# Security & API Status -## Supported Versions +## Reporting a Security Vulnerability -Use this section to tell people about which versions of your project are -currently being supported with security updates. +If you find a security issue (e.g. credentials being logged, an endpoint leaking data), please **do not open a public issue**. Open a [GitHub Security Advisory](https://github.com/sameerk27/vigil365/security/advisories/new) instead so it can be fixed before public disclosure. -| Version | Supported | -| ------- | ------------------ | -| 5.1.x | :white_check_mark: | -| 5.0.x | :x: | -| 4.0.x | :white_check_mark: | -| < 4.0 | :x: | +--- -## Reporting a Vulnerability +## Reporting a Broken Graph API Endpoint -Use this section to tell people how to report a vulnerability. +Microsoft occasionally changes, deprecates, or moves Graph API endpoints. If a dashboard card stops working or shows a permission error, please open an issue using this format: -Tell them where to go, how often they can expect to get an update on a -reported vulnerability, what to expect if the vulnerability is accepted or -declined, etc. +**Title:** `[BROKEN API] — ` + +**Include:** +- Which page/card is affected (e.g. "Identity page — Risk Detections card") +- The error shown on screen (e.g. "403 Forbidden" or "404 Not Found") +- Your approximate date when it broke +- Link to the Microsoft changelog entry if you found one + +--- + +## Known API Stability + +| Endpoint area | Stability | Notes | +|--------------|-----------|-------| +| Risky users / sign-ins | ✅ Stable | v1.0, unchanged since 2021 | +| MFA registration details | ✅ Stable | v1.0 | +| Intune device compliance | ✅ Stable | v1.0 | +| Conditional Access policies | ✅ Stable | v1.0 | +| Defender XDR alerts (`alerts_v2`) | ✅ Stable | v1.0, replaced `alerts` in 2022 | +| Defender XDR incidents | ✅ Stable | v1.0 | +| Service health | ✅ Stable | v1.0 | +| Audit logs / sign-ins | ✅ Stable | v1.0 | +| Attack simulation | ⚠️ Watch | v1.0 but feature-flagged by license | +| Insider Risk (IRM) | ⚠️ Watch | Requires Microsoft Purview license | +| Identity health issues | ⚠️ Beta | `/beta/` endpoint — may change without notice | +| MCAS alerts | ⚠️ Watch | Merging into Defender XDR over time | + +--- + +## Staying Ahead of Changes + +Subscribe to the official Microsoft Graph changelog to get notified of breaking changes: + +🔗 [https://developer.microsoft.com/en-us/graph/changelog](https://developer.microsoft.com/en-us/graph/changelog) + +--- + +## How the App Handles Broken Endpoints + +Each dashboard card fetches independently. If one Graph endpoint returns an error (403, 404, 429), that card shows an inline error message — **all other pages and cards keep working**. No single API change can break the whole dashboard.