Skip to content

Security: CoreLinkPlatform/mock-server

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Report suspected vulnerabilities privately by email

Include, where possible:

  • affected repository and version;
  • vulnerability description;
  • reproduction steps;
  • expected and actual behavior;
  • potential impact;
  • suggested mitigation;
  • relevant logs or screenshots with sensitive information removed.

Do not include:

  • access tokens;
  • client secrets;
  • private keys;
  • customer data;
  • production credentials;
  • unnecessary personally identifiable information.
  • Response process

We aim to:

acknowledge reports within 5 business days; investigate and assess severity; coordinate remediation and disclosure; publish security advisories when appropriate.

These targets are not contractual service-level guarantees.

Supported versions

Until the first stable release, only the latest published preview version is evaluated for security updates.

After stable releases begin, supported versions will be listed here.

Scope

Security reports may include:

authentication and authorization bypass; tenant isolation failures; credential exposure; command execution vulnerabilities; webhook signature bypass; request forgery; unsafe SDK behavior; dependency vulnerabilities with demonstrated impact; MCP tool authorization or data-exposure issues.

General support requests and feature requests should use the repository issue tracker.

There aren't any published security advisories