Skip to content

Security: hmlendea/nuciweb.http

SECURITY.md

Security Policy

This security policy describes how security vulnerabilities are managed in the NuciWeb.HTTP library, a lightweight .NET library for HTTP and network utilities. Security reports are investigated privately, and coordinated disclosure is practised to ensure appropriate remediation before public disclosure.

πŸ“‘ Table of Contents

πŸ›‘οΈ Supported Versions

Use this table to indicate which project versions currently receive security maintenance.

Version Distribution Channel Supported
Latest version NuGet βœ…
Latest version GitHub Releases βœ…
Preceding versions Any distribution channel ❌

🚨 Reporting a Vulnerability

Please do not disclose suspected vulnerabilities publicly before maintainers have had an opportunity to validate and remediate them.

To report a vulnerability:

πŸ“Œ Scope

The subsequent report categories are in scope for this repository:

  • Vulnerabilities in the NuciWeb.HTTP library code
  • Security issues affecting the public API and functionality
  • Dependency vulnerabilities that impact library security

The subsequent categories are out of scope unless explicitly stated to the contrary:

  • Security issues in applications using this library
  • Vulnerabilities in third-party dependencies that do not affect this library
  • General .NET runtime or framework vulnerabilities

πŸ“’ Disclosure Policy

This project follows coordinated disclosure:

  1. Vulnerabilities are investigated privately.
  2. A remediation plan is prepared and validated.
  3. Public disclosure is published after a fix, mitigation, or agreed risk decision is available.
  4. Credit is attributed in accordance with reporter preference and project policy.

🧾 Safe Harbour

If your research is conducted in good faith, confined to authorised scope, and disclosed responsibly, the maintainers will not pursue action for policy-compliant activity.

There aren't any published security advisories