Skip to content

Security: mcpdesc/mcpdesc.org

Security

SECURITY.md

Security Policy

Reporting a vulnerability

This repository hosts a static website with no backend. Still, if you discover a security issue — for example a content injection vector, a dependency vulnerability, or a misconfiguration in the deployment/headers — please report it responsibly.

Please include:

  • A description of the issue and its potential impact.
  • Steps to reproduce, if applicable.
  • Any relevant URLs, request/response details, or configuration.

Scope

In scope:

  • This website's code, configuration, and deployment (Cloudflare Pages, security headers in public/_headers).
  • The client-side analytics plugin (src/analytics/).

Out of scope:

  • Issues with an tool that is listed in the curated list. For any issue with a particular tool, refer to the source repo for instructions on how to report an issue.

Supported versions

The live site is built from the main branch. Only main is supported.

There aren't any published security advisories