Skip to content

Security: evolution-cms/eMCP

Security

SECURITY.md

SECURITY — eMCP

Supported Scope

Security disclosures are accepted for current mainline work and all tagged stable releases.

Reporting a Vulnerability

  • Send a private report to project maintainers (do not open public issue first).
  • Include: impact summary, reproduction steps, affected versions, and suggested mitigation.
  • If possible, include a minimal proof of concept.

Disclosure Policy

  • Maintainers acknowledge receipt within 3 business days.
  • Triage target: initial severity assessment within 7 business days.
  • A fix timeline is shared after triage.
  • Public disclosure is coordinated after patch availability.

Out of Scope

  • Reports that require non-default insecure deployment settings only.
  • Non-exploitable style or documentation issues without security impact.

Security Baseline References

  • SECURITY_CHECKLIST.md
  • THREAT_MODEL.md
  • SPEC.md security and authorization sections

There aren’t any published security advisories