Skip to content

Security: mcpdesc/.github

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, report them privately by email to security@mcpdesc.org. Where possible, use GitHub's private security advisories on the affected repository.

Please include:

  • A description of the issue and its impact
  • Steps to reproduce (proof-of-concept if available)
  • Affected repository, package, and version

We will acknowledge your report, keep you informed of progress, and credit you in the fix (unless you prefer to remain anonymous).

Supported versions

These projects are pre-1.0 and evolving. Security fixes are applied to the latest released version of each package. Pin versions and watch releases for updates.

Scope

The mcpdesc projects are static rulesets, specifications, and tooling. Please consider the typical trust boundaries (untrusted input documents, CI execution) when reporting.

There aren't any published security advisories