Skip to content

Security: MikeInNs/CorePin

Security

SECURITY.md

Security Policy

CorePin's detailed security notes are maintained in docs/SECURITY.md.

Reporting a Security Issue

If you believe you found a security issue:

  1. Do not post exploit details in a public issue.
  2. Open a minimal issue asking for maintainer contact, or use any private contact method published by the project maintainer.
  3. Include the CorePin version, Windows version, and a concise description.
  4. Include whether the issue requires administrator rights or service installation.
  5. Share proof-of-concept details privately after contact is established.

CorePin is a local Windows utility with a local service. It does not expose a network API or remote management endpoint. Security-sensitive areas include service installation, elevated operations, process affinity changes, power-plan changes, OpenXR runtime changes, and local files under C:\ProgramData\CorePin.

Supported Versions

CorePin is a personal, spare-time project with no guaranteed support or security fix timeline. Unless a release states otherwise, only the latest public release is considered for a possible security fix. Reporting a vulnerability does not guarantee a response, fix, or new release, although responsible private reports are appreciated.

There aren't any published security advisories