Skip to content

Security: Shanu231/LibraCore

Security

SECURITY.md

Security Policy

We take the security of LibraCore Enterprise seriously. If you believe you have found a security vulnerability, please report it to us responsibly using the guidelines below.


Supported Versions

Only the latest stable release of LibraCore is actively supported with security updates.

Version Supported
1.0.x ✅
< 1.0 ❌

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Instead, please send an email to the project maintainers containing details of the security issue.

What to Include

To help us assess and resolve the issue quickly, please include:

  • A detailed description of the vulnerability.
  • Steps to reproduce the issue (including any proof-of-concept scripts or commands).
  • The potential impact (e.g., SQL injection, privilege escalation).
  • Any recommendations or patches you suggest.

Security Response Process

Upon receipt of a vulnerability report, the maintenance team will:

  1. Acknowledge receipt of the report within 48 hours.
  2. Work to verify and fix the vulnerability in a secure workspace.
  3. Coordinate a patch release within 30 days of validation.
  4. Provide appropriate credit to the reporter in the changelog (unless requested otherwise).

There aren't any published security advisories