We take the security of LibraCore Enterprise seriously. If you believe you have found a security vulnerability, please report it to us responsibly using the guidelines below.
Only the latest stable release of LibraCore is actively supported with security updates.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
Please do not open a public GitHub issue for security vulnerabilities.
Instead, please send an email to the project maintainers containing details of the security issue.
To help us assess and resolve the issue quickly, please include:
- A detailed description of the vulnerability.
- Steps to reproduce the issue (including any proof-of-concept scripts or commands).
- The potential impact (e.g., SQL injection, privilege escalation).
- Any recommendations or patches you suggest.
Upon receipt of a vulnerability report, the maintenance team will:
- Acknowledge receipt of the report within 48 hours.
- Work to verify and fix the vulnerability in a secure workspace.
- Coordinate a patch release within 30 days of validation.
- Provide appropriate credit to the reporter in the changelog (unless requested otherwise).