Core-Web-Hub

Security Policy

Supported Versions

We release security updates for the following versions of Core Web:

Version Supported
1.x.x :white_check_mark:
< 1.0 :x:

Reporting a Vulnerability

If you discover a security vulnerability in Core Web, please follow these steps:

  1. Do not create a public issue on GitHub
  2. Send an email to our security team at security@core-web.example.com
  3. Include the following information in your report:
    • Description of the vulnerability
    • Steps to reproduce the issue
    • Potential impact of the vulnerability
    • Any possible mitigations you’ve identified

Response Time

We strive to respond to security vulnerability reports within 48 hours. Our team will:

  1. Acknowledge receipt of your report
  2. Investigate the issue
  3. Develop and test a fix
  4. Release a security update
  5. Publicly disclose the vulnerability (credit given to reporters)

Security Measures

Core Web implements several security measures:

Known Vulnerabilities

We are aware of the following security vulnerabilities in our dependencies:

RSA Timing Attack (RUSTSEC-2023-0071)

We actively monitor security advisories and work to address vulnerabilities as quickly as possible.

Security Best Practices

When using Core Web in your projects, we recommend:

Additional Resources