Skip to content

Security: 3maem/ashcore

Security

SECURITY.md

Security Policy

Security is the core mission of ASH.

ASH is a security-focused library designed to protect applications from request tampering, replay attacks, and data manipulation. We take all security issues seriously and respond quickly.


Reporting a Vulnerability

If you discover a security vulnerability or potential exploit:

❌ DO NOT open a public issue

❌ DO NOT disclose it publicly

Please report it privately to:

security@ashcore.com

Include:

  • Description of the issue
  • Steps to reproduce
  • Proof of concept (if available)
  • Affected versions
  • Potential impact

Response Timeline

We aim to:

  • Acknowledge within 48 hours
  • Investigate promptly
  • Provide fixes as quickly as possible
  • Coordinate responsible disclosure

Critical vulnerabilities are prioritized immediately.


Responsible Disclosure

We follow responsible disclosure practices:

  1. Issue is reported privately
  2. We validate and patch
  3. Security release is prepared
  4. Public advisory is published
  5. Credit is given to the reporter (optional)

We appreciate ethical security research.


Supported Versions

Security patches are provided for:

  • Latest major version
  • Latest minor versions only

Older versions may not receive fixes.

Please upgrade regularly.


Security Best Practices

When using ASH:

  • Always use HTTPS
  • Keep dependencies updated
  • Do not expose secrets in client-side code
  • Rotate keys regularly
  • Use latest version

ASH improves security, but correct configuration is essential.


Thanks

Security is a shared responsibility.

Thank you for helping keep the ecosystem safe.

There aren’t any published security advisories