Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Report suspected vulnerabilities privately by email
Include, where possible:
- affected repository and version;
- vulnerability description;
- reproduction steps;
- expected and actual behavior;
- potential impact;
- suggested mitigation;
- relevant logs or screenshots with sensitive information removed.
Do not include:
- access tokens;
- client secrets;
- private keys;
- customer data;
- production credentials;
- unnecessary personally identifiable information.
- Response process
acknowledge reports within 5 business days; investigate and assess severity; coordinate remediation and disclosure; publish security advisories when appropriate.
These targets are not contractual service-level guarantees.
Until the first stable release, only the latest published preview version is evaluated for security updates.
After stable releases begin, supported versions will be listed here.
Security reports may include:
authentication and authorization bypass; tenant isolation failures; credential exposure; command execution vulnerabilities; webhook signature bypass; request forgery; unsafe SDK behavior; dependency vulnerabilities with demonstrated impact; MCP tool authorization or data-exposure issues.
General support requests and feature requests should use the repository issue tracker.