Skip to content

Revise security policy and reporting instructions#5096

Merged
theCyberTech merged 3 commits intomainfrom
theCyberTech-patch-1
Mar 26, 2026
Merged

Revise security policy and reporting instructions#5096
theCyberTech merged 3 commits intomainfrom
theCyberTech-patch-1

Conversation

@theCyberTech
Copy link
Copy Markdown
Member

Updated the security reporting process and contact details.

Updated the security reporting process and contact details.
Copilot AI review requested due to automatic review settings March 26, 2026 02:37
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the repository’s security policy to reflect a revised vulnerability reporting process and updated contact details.

Changes:

  • Simplifies the SECURITY policy text to a shorter statement of intent.
  • Switches reporting instructions to a Bugcrowd submission email.
  • Adds explicit guidance not to disclose vulnerabilities publicly and to use the designated reporting path.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

theCyberTech and others added 2 commits March 26, 2026 10:42
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Copy link
Copy Markdown
Contributor

@iris-clawd iris-clawd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good — clean swap to the Bugcrowd VDP. All the detailed reporting guidance (scope, safe harbor, etc.) lives on the Bugcrowd side now so removing it from the repo makes sense. 👍

@theCyberTech theCyberTech merged commit a91cd1a into main Mar 26, 2026
46 checks passed
@theCyberTech theCyberTech deleted the theCyberTech-patch-1 branch March 26, 2026 02:50
iris-clawd added a commit that referenced this pull request Mar 26, 2026
Add a 'Reporting Security Vulnerabilities' section to the MCP security
documentation across all languages (en, pt-BR, ko, ar) directing users
to report via the Bugcrowd VDP (crewai-vdp-ess@submit.bugcrowd.com).

This aligns the docs with the updated security policy from PR #5096,
which transitioned vulnerability reporting to Bugcrowd.
iris-clawd added a commit that referenced this pull request Mar 26, 2026
Create a dedicated Security Policy page (docs/{en,pt-BR,ko,ar}/security.mdx)
with vulnerability reporting instructions pointing to the Bugcrowd VDP
(crewai-vdp-ess@submit.bugcrowd.com), consistent with the updated security
policy from PR #5096.

The page is added to the Documentation tab navigation (after Telemetry)
across all versions and languages in docs.json.

This is a top-level security page, not buried inside MCP docs.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants