SECURITY.md
markdown
sha256:87f84653ce4706be8c65b0c4494ed6fb891213cca82db2b1824772cddc41a752
feat(auth): durable MCP OAuth refresh via shared strong sto…
Agent
minor
61 days ago
Security Policy
Supported Versions
Security fixes are applied to the latest commit on the main branch. No separate release branches are maintained at this time.
| Version | Supported |
|---|---|
main (latest) |
Yes |
| Older commits | No |
Reporting a Vulnerability
Please do not report security vulnerabilities through public GitHub issues.
Report security issues privately using one of these methods:
- GitHub Security Advisories (preferred): Use the Report a vulnerability link on the Security tab of this repository. GitHub will keep the report private until a fix is coordinated.
- Email: Send details to the repository owner through the contact information on the GitHub profile.
What to include
- Description of the vulnerability and affected component(s)
- Steps to reproduce (or a proof-of-concept if available)
- Potential impact (data exposure, authentication bypass, privilege escalation, etc.)
- Any suggested fix if you have one
Response timeline
- Acknowledgement: within 3 business days
- Initial assessment: within 7 business days
- Fix and coordinated disclosure: timeline depends on severity; critical issues are prioritized
Scope
In scope:
hub/gateway/— OAuth, JWT, image proxy, billinghub/bridge/— GitHub integration, vault sync, team roleshub/icp/— ICP canister (Motoko)lib/— core library (search, memory, importers, AIR)mcp/— MCP servercli/— CLIweb/hub/— Hub frontend
Out of scope:
- Self-hosted deployments that use default or weak secrets in
config/local.yamlor.env - Vulnerabilities that require physical access to the server
- Denial-of-service attacks against self-hosted instances
- Third-party services (GitHub OAuth, Stripe, Netlify, Internet Computer)
Security hardening
This codebase has completed a 4-phase pre-launch security audit (Phases 0–3). See docs/SECURITY-AUDIT-PLAN.md for the full remediation record.
File History
4 commits
sha256:87f84653ce4706be8c65b0c4494ed6fb891213cca82db2b1824772cddc41a752
feat(auth): durable MCP OAuth refresh via shared strong sto…
Agent
minor
61 days ago
sha256:873e30b7fafe601346295f8f4289f388f21d8f715f28584d5481899ba2b714fc
Merge pull request #249 from aaronrene/muse-mirror
Agent
78 days ago
sha256:d8c648b20a4d53b2673c5c082ee7edfa7b2fc9b11080832da1f38807b6bf940b
fix(7C-L1b): route hosted delegation proposals through cani…
Human
minor
⚠
81 days ago
sha256:2827ba9e7632a4b141c50caf1e8f7d77abbc3515be20e7465f2bccb0ac4edf91
fix: repair endpoint now sets has_active_subscription when …
Human
minor
⚠
101 days ago