Skip to content

Commit 46f9ab2

Browse files
Revise security policy and supported versions (#1123)
Updated supported versions and reporting guidelines for vulnerabilities.
1 parent a880d84 commit 46f9ab2

File tree

1 file changed

+44
-0
lines changed

1 file changed

+44
-0
lines changed

SECURITY.md

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
# Security Policy
2+
3+
## Supported Versions
4+
5+
The following versions of Context7 MCP are currently supported with security updates:
6+
7+
| Version | Supported |
8+
| ------- | ------------------ |
9+
| 1.0.x | :white_check_mark: |
10+
11+
We recommend always using the latest version (`@upstash/context7-mcp@latest`) to ensure you have the most recent security patches and features.
12+
13+
## Reporting a Vulnerability
14+
15+
We take the security of Context7 seriously. If you discover a security vulnerability, please report it responsibly.
16+
17+
### How to Report
18+
19+
- Please use GitHub's [private vulnerability reporting](https://github.com/upstash/context7/security/advisories/new) feature to submit your report
20+
- Alternatively, you can email security concerns to [[email protected]](mailto:[email protected])
21+
22+
### What to Include
23+
24+
- A description of the vulnerability
25+
- Steps to reproduce the issue
26+
- Potential impact of the vulnerability
27+
- Any suggested fixes (optional)
28+
29+
### What to Expect
30+
31+
- **Initial Response**: We aim to acknowledge your report within 48 hours
32+
- **Status Updates**: You can expect updates on the progress every 5-7 business days
33+
- **Resolution Timeline**: We strive to resolve critical vulnerabilities within 30 days
34+
35+
### After Reporting
36+
37+
- If the vulnerability is accepted, we will work on a fix and coordinate disclosure with you
38+
- We will credit reporters in our release notes (unless you prefer to remain anonymous)
39+
- If the report is declined, we will provide an explanation
40+
41+
### Please Do Not
42+
43+
- Disclose the vulnerability publicly before we have addressed it
44+
- Exploit the vulnerability beyond what is necessary to demonstrate it

0 commit comments

Comments
 (0)