This security policy describes how security vulnerabilities are managed in the NuciWeb.HTTP library, a lightweight .NET library for HTTP and network utilities. Security reports are investigated privately, and coordinated disclosure is practised to ensure appropriate remediation before public disclosure.
Use this table to indicate which project versions currently receive security maintenance.
| Version | Distribution Channel | Supported |
|---|---|---|
| Latest version | NuGet | β |
| Latest version | GitHub Releases | β |
| Preceding versions | Any distribution channel | β |
Please do not disclose suspected vulnerabilities publicly before maintainers have had an opportunity to validate and remediate them.
To report a vulnerability:
- GitHub Security Advisories
- Contact the maintainers directly
The subsequent report categories are in scope for this repository:
- Vulnerabilities in the NuciWeb.HTTP library code
- Security issues affecting the public API and functionality
- Dependency vulnerabilities that impact library security
The subsequent categories are out of scope unless explicitly stated to the contrary:
- Security issues in applications using this library
- Vulnerabilities in third-party dependencies that do not affect this library
- General .NET runtime or framework vulnerabilities
This project follows coordinated disclosure:
- Vulnerabilities are investigated privately.
- A remediation plan is prepared and validated.
- Public disclosure is published after a fix, mitigation, or agreed risk decision is available.
- Credit is attributed in accordance with reporter preference and project policy.
If your research is conducted in good faith, confined to authorised scope, and disclosed responsibly, the maintainers will not pursue action for policy-compliant activity.