Skip to content

Security: clappingmonkey/zuul-mcp

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.x

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

Do NOT open a public GitHub issue for security vulnerabilities.

Please use GitHub Security Advisories:

  1. Go to Report a vulnerability
  2. Provide a clear description of the issue
  3. Include steps to reproduce if possible

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 7 days
  • Fix or mitigation: Best effort within 30 days, depending on severity

Disclosure Policy

We follow coordinated disclosure. Please allow reasonable time to address the issue before making it public.

Out of Scope

  • Vulnerabilities in Zuul CI itself (report to Zuul's security process)
  • Denial of service via large API responses (expected behavior with remote APIs)

There aren't any published security advisories