https://devblogs.microsoft.com/dotnet/announcing-dotnet-security-group/ Skip to main content [RE1Mu3b] Microsoft Dev Blogs Dev Blogs Dev Blogs * Home * Developer + Microsoft for Developers + Visual Studio + Visual Studio Code + Develop from the cloud + All things Azure + Xcode + DevOps + Windows Developer + Developer support + ISE Developer + Engineering@Microsoft + Azure SDK + Command Line + Perf and Diagnostics + React Native * Technology + AutoGen + DirectX + OpenAPI + Semantic Kernel + SurfaceDuo + Windows AI Platform * Languages + C++ + C# + F# + TypeScript + PowerShell Community + PowerShell Team + Python + JavaScript + Java + Java Blog in Chinese + Go * .NET + All .NET posts + .NET Aspire + .NET MAUI + AI + ASP.NET Core + Blazor + Entity Framework + NuGet + Servicing + .NET Blog in Chinese * Platform Development + #ifdef Windows + Azure AI Foundry + Azure Government + Azure VM Runtime Team + Bing Dev Center + Microsoft Edge Dev + Microsoft Azure + Microsoft 365 Developer + Microsoft Entra Identity Developer + Old New Thing + Power Platform + Windows MIDI and Music dev * Data Development + Azure Cosmos DB + Azure Data Studio + Azure SQL + OData + Revolutions R + SQL Server Data Tools + Unified Data Model (IDEAs) * More [ ] Search Search * No results Cancel * Dev Blogs * .NET Blog * Announcing the .NET Security Group Visual Studio 2026 Insiders is here! The world's most popular IDE just got an upgrade. Download Now Learn More October 14th, 2025 0 reactions Announcing the .NET Security Group Jamshed Damkewala Jamshed Damkewala Principal PM Manager Show more The .NET project is run by Microsoft and follows our security reporting and disclosure practices. We publish vulnerability fixes and disclosures most months on Patch Tuesday. Nothing about that is changing. We are announcing the .NET Security Group, a group of organizations that will collaborate on delivering security fixes to the broadest set of .NET users, simultaneously with Microsoft. We're all better served by getting more deployments patched, quickly and predictably. We're believers in the concept of upstream open source projects. That includes sharing vulnerability information with other organizations that distribute .NET. We've done that with a small set of companies since 2016, starting with Red Hat. Members receive source patches prior to public disclosure so that binary packages can be built, validated, and published at the same time as Microsoft. Membership of this group has been private, by invitation only, and grew to include Canonical, IBM, Red Hat, and Microsoft. That's how the .NET Security Group started. We are expanding the program to enable organizations that ship their own distribution of .NET to have the same ability to better protect their users. By sharing information about vulnerabilities with trusted partners early, we hope to reduce the time between public disclosure of CVEs and when updates are available for distributions other than Microsoft's. We believe this will help strengthen the security of the .NET ecosystem. If you're shipping your own distribution of .NET and interested in joining the group you can apply by completing this .NET Security Group Application. Why did we do this? Security isn't just a feature - it's a core value that enables users to innovate with confidence. It is foundational to the trust .NET users place in the platform. With .NET powering workloads across finance, healthcare, government, and other critical industry verticals, even minor vulnerabilities can have outsized impact. Users expect Microsoft to deliver secure-by-default frameworks and rapidly respond to CVEs. We deliver on these expectations today for the Microsoft distribution of .NET. Multiple organizations build .NET from source and ship their own distribution of .NET to their users. Several Linux distributions do this, as do independent software vendors (across both Windows and Linux). In fact, we worked in collaboration with these same organizations to reduce the cost of building .NET, resulting in the dotnet/dotnet repo. We want it to be straightforward and low-cost to distribute security fixes to users. More recently, other organizations came to us asking if they could get access to patches for their End-of-Life servicing businesses. These requests made us realize that it was time to publicize the .NET Security Group and better define its goals. Program members need to be active participants in the .NET upstream project and publish builds for supported .NET versions. Doing that demonstrates a strong commitment to the ecosystem and earned credibility to all participants. As the maintainer of a critical upstream project, it is important for us to secure all major distributions of .NET, our own and those distributed by partner organizations. This change, to expand and publicize the .NET Security Group, will enable us to do just that. What to expect Here's what you can expect when applying to join the .NET Security Group. Flowchart showing 5-step process: Application, Vetting, Approval, Agreement Signing, and Onboarding 1. Software vendors that want to join the .NET Security Group must complete an intake form. 2. Given the confidential nature of information shared during the program we need to ensure a high degree of trust. Partners will be vetted to confirm business authenticity, security risks, and validated against Trade Sanctions/Do Not Engage/Watch Lists. This vetting can typically take a few days to weeks based on how complete the information provided in the intake form is. Group members will be re-vetted on an annual basis, and the agreement will be renewed for another 1-year term. 3. Based on results of the vetting the partner will be approved for membership in the group. In the unlikely event the vetting cannot be completed with the information provided we may reach out for additional information. 4. Approved members will sign a program agreement outlining the terms of group membership. If a Non-Disclosure Agreement (NDA) is not already in place between the applicant and Microsoft they will also sign an NDA. 5. After this, they will be onboarded into the group. Once onboarded, program members will receive information about CVEs in supported versions of .NET about a week before public disclosure each month. Closing If you're shipping your own distribution of .NET today and interested in joining the .NET Security Group you can apply by completing the .NET Security Group Application. 0 * * * * * * 0 0 * Facebook Share on Facebook * Share on X * LinkedIn Share on Linkedin Category .NETLifecycleMaintenance & Updates Topics PartnersPatchingSecuritySupport Share * * * Author Jamshed Damkewala Jamshed Damkewala Principal PM Manager Jamshed Damkewala is a Principal PM Manager on the .NET team. 0 comments Be the first to start the discussion. Leave a commentCancel reply Sign in [ ] [Reply] [Cancel] Code of Conduct Read next October 8, 2025 Preparing for the .NET 10 GC (DATAS) maoni maoni October 7, 2025 Developer and AI Code Reviewer: Reviewing AI-Generated Code in .NET Wendy Breiding (SHE/HER) Wendy Breiding (SHE/HER) Stay informed Get notified when new posts are published. [ ] Subscribe By subscribing you agree to our Terms of Use and Privacy Follow this blog facebook linkedinyoutubetwitch Stackoverflow Are you sure you wish to delete this comment? OK Cancel Sign in Theme Insert/edit link Close Enter the destination URL URL [ ] Link Text [ ] [ ] Open link in a new tab Or link to existing content Search [ ] No search term specified. Showing recent items. Search or use up and down arrow keys to select an item. Cancel [Add Link] Code Block x Paste your code snippet [ ] Ok Cancel What's new * Surface Pro * Surface Laptop * Surface Laptop Studio 2 * Copilot for organizations * Copilot for personal use * AI in Windows * Explore Microsoft products * Windows 11 apps Microsoft Store * Account profile * Download Center * Microsoft Store support * Returns * Order tracking * Certified Refurbished * Microsoft Store Promise * Flexible Payments Education * Microsoft in education * Devices for education * Microsoft Teams for Education * Microsoft 365 Education * How to buy for your school * Educator training and development * Deals for students and parents * AI for education Business * Microsoft Cloud * Microsoft Security * Dynamics 365 * Microsoft 365 * Microsoft Power Platform * Microsoft Teams * Microsoft 365 Copilot * Small Business Developer & IT * Azure * Microsoft Developer * Microsoft Learn * Support for AI marketplace apps * Microsoft Tech Community * Azure Marketplace * AppSource * Visual Studio Company * Careers * About Microsoft * Company news * Privacy at Microsoft * Investors * Diversity and inclusion * Accessibility * Sustainability Your Privacy Choices Your Privacy Choices Consumer Health Privacy * Sitemap * Contact Microsoft * Privacy * Manage cookies * Terms of use * Trademarks * Safety & eco * Recycling * About our ads * (c) Microsoft 2025