Skip to content

Security: php-workx/modal-mcp

SECURITY.md

Security Policy

Supported disclosures

Report vulnerabilities privately. Do not open a public issue, post a proof of concept in a discussion, or share exploit details in a public channel before a fix is available.

Use the GitHub Security Advisory flow for private reporting. If that is not available to you, open a minimal issue that asks for a private contact channel and avoid including exploit steps, payloads, or secrets.

What to include

Provide:

  • a short summary of the issue
  • affected versions or commits, if known
  • impact and attack surface
  • reproduction notes, if safe to share
  • any mitigation you have already identified

Response expectations

We aim to acknowledge reports promptly, triage them privately, and coordinate a fix before public disclosure. Severity, complexity, and release timing determine the exact response window.

Disclosure posture

Security fixes are expected to land through the normal review and CI path, then ship in a signed release tag after validation. Public advisories should name the fixed version only after the release is available.

There aren't any published security advisories