Skip to content

Security: ov3rde/TA_MCP_admin

Security

SECURITY.md

Security Policy

Supported Releases

  • Security fixes, when provided, apply to the latest tagged release and the current default branch of this app repository.
  • Older package versions on GitHub or Splunkbase should be treated as unsupported unless maintainers explicitly state otherwise.

Reporting A Vulnerability

  • Do not post exploit details, secrets, tokens, or harmful reproduction data in a public issue.
  • If GitHub private vulnerability reporting is enabled for this repository, use that channel first.
  • If private reporting is not available, open a minimal public issue that asks for a private contact path without disclosing exploit details.

Response Model

  • This app does not come with any support obligation, response-time guarantee, SLA, or contractual maintenance commitment.
  • Security reports may be reviewed on a purely voluntary, best-effort basis.
  • There is no obligation to respond, investigate, provide a fix, publish an update, or backport a patch.
  • If fixes are made available, they may be published on GitHub first and then packaged for Splunk deployment.

Scope

  • Report issues that could lead to unauthorized access, token disclosure, privilege escalation, destructive actions, or data exfiltration.
  • Configuration mistakes should include the exact app version, Splunk version, deployment mode, and the smallest safe reproduction.

There aren’t any published security advisories