SECURITY.md
markdown
sha256:b5f647cb9c409f563d4671fe3fc05ddea01fabfed9b41fc11cb923588e1c1baf
mirror: GitHub Phase A durable MCP OAuth (#270)
Human
minor
⚠ breaking
12 days ago
Security Policy
Supported Versions
Security fixes are applied to the latest commit on the main branch. No separate release branches are maintained at this time.
| Version | Supported |
|---|---|
main (latest) |
Yes |
| Older commits | No |
Reporting a Vulnerability
Please do not report security vulnerabilities through public GitHub issues.
Report security issues privately using one of these methods:
- GitHub Security Advisories (preferred): Use the Report a vulnerability link on the Security tab of this repository. GitHub will keep the report private until a fix is coordinated.
- Email: Send details to the repository owner through the contact information on the GitHub profile.
What to include
- Description of the vulnerability and affected component(s)
- Steps to reproduce (or a proof-of-concept if available)
- Potential impact (data exposure, authentication bypass, privilege escalation, etc.)
- Any suggested fix if you have one
Response timeline
- Acknowledgement: within 3 business days
- Initial assessment: within 7 business days
- Fix and coordinated disclosure: timeline depends on severity; critical issues are prioritized
Scope
In scope:
hub/gateway/— OAuth, JWT, image proxy, billinghub/bridge/— GitHub integration, vault sync, team roleshub/icp/— ICP canister (Motoko)lib/— core library (search, memory, importers, AIR)mcp/— MCP servercli/— CLIweb/hub/— Hub frontend
Out of scope:
- Self-hosted deployments that use default or weak secrets in
config/local.yamlor.env - Vulnerabilities that require physical access to the server
- Denial-of-service attacks against self-hosted instances
- Third-party services (GitHub OAuth, Stripe, Netlify, Internet Computer)
Security hardening
This codebase has completed a 4-phase pre-launch security audit (Phases 0–3). See docs/SECURITY-AUDIT-PLAN.md for the full remediation record.
File History
3 commits
sha256:b5f647cb9c409f563d4671fe3fc05ddea01fabfed9b41fc11cb923588e1c1baf
mirror: GitHub Phase A durable MCP OAuth (#270)
Human
minor
⚠
12 days ago
sha256:d8c648b20a4d53b2673c5c082ee7edfa7b2fc9b11080832da1f38807b6bf940b
fix(7C-L1b): route hosted delegation proposals through cani…
Human
minor
⚠
31 days ago
sha256:2827ba9e7632a4b141c50caf1e8f7d77abbc3515be20e7465f2bccb0ac4edf91
fix: repair endpoint now sets has_active_subscription when …
Human
minor
⚠
51 days ago