Skip to content

Security: andygeiss/mcp

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest minor release receives security fixes.

Version Supported
Latest Yes
Older No

Reporting a Vulnerability

Do NOT open a public issue.

Use GitHub Security Advisories to report vulnerabilities privately.

Response Timeline

  • Acknowledgment: within 72 hours
  • Assessment: within 7 days
  • Fix target: within 30 days for confirmed issues

Scope

  • The MCP server binary (cmd/mcp) is in scope
  • The cmd/scaffold template rewriter is not security-critical

Bug Bounty

There is no formal bug bounty program.

There aren't any published security advisories