Skip to content

Security: host-uk/core

SECURITY.md

Security Policy

Supported Versions

Package Supported
core (Go CLI) Latest
core-php Latest
core-* modules Latest

Reporting a Vulnerability

Do not open a public issue for security vulnerabilities.

Please report security issues via GitHub's private vulnerability reporting:

  1. Go to the affected repository
  2. Click "Security" tab
  3. Click "Report a vulnerability"

Or email: security@host.uk.com (if available)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Fix timeline: Depends on severity
    • Critical: 24-48 hours
    • High: 1 week
    • Medium: 2 weeks
    • Low: Next release

Scope

In scope:

  • All core-* packages
  • The core CLI
  • Infrastructure code in this organisation

Out of scope:

  • Third-party dependencies (report upstream)
  • Social engineering
  • DoS attacks

Recognition

We credit security researchers in release notes (unless anonymity is requested).

There aren’t any published security advisories