Skip to content

Security: bluewhitep/race-mcp

Security

SECURITY.md

Security Policy

Supported Versions

The current maintained line is 0.3.x. Security fixes are made on the default branch first and may be released as a patch version.

Reporting A Vulnerability

Do not publish exploit details in a public issue.

Preferred reporting path:

  1. Use GitHub private vulnerability reporting or a GitHub Security Advisory for this repository when it is enabled.
  2. If private vulnerability reporting is not enabled yet, open a public issue that only requests a private security coordination channel. Do not include exploit code, secret values, private infrastructure details, or proof-of-concept payloads in that public issue.

Expected response:

  • Initial maintainer acknowledgement target: 7 days.
  • Triage target: 14 days after acknowledgement.
  • Fix and disclosure timing depend on severity, exploitability, and available validation evidence.

Security Scope

Security-sensitive areas include:

  • SSH execution and transfer boundaries.
  • Local approval and Full Access gates.
  • Audit, backup, and rollback records.
  • MCP server exposure and loopback-only server behavior.
  • PyPI and GitHub Actions release credentials.

Disclosure

Coordinated disclosure is preferred. Public disclosure should wait until a fix, mitigation, or explicit maintainer decision is available.

There aren't any published security advisories