Skip to content

Commit 2e16bc8

Browse files
claude[bot]claude
andauthored
docs: point SECURITY.md at GitHub Security Advisories (v1.x) (#3602)
Co-authored-by: Claude <noreply@anthropic.com>
1 parent 8c2fa6e commit 2e16bc8

1 file changed

Lines changed: 26 additions & 6 deletions

File tree

‎SECURITY.md‎

Lines changed: 26 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,35 @@
11
# Security Policy
22

3-
Thank you for helping us keep the SDKs and systems they interact with secure.
3+
Thank you for helping keep the Model Context Protocol and its ecosystem secure.
4+
5+
## Supported Versions
6+
7+
| Version | Line | Support |
8+
| ---------------------------------------- | ----------------------- | ------------------------------------------- |
9+
| 2.x (newest release) | current stable (`main`) | bug fixes, security fixes, new features |
10+
| 1.x newest release (`v1.x` branch) | maintenance | critical bug fixes and security fixes |
11+
| older 1.x releases, and all pre-releases | unsupported | upgrade to the newest 1.x release or to 2.x |
12+
13+
Only the newest release of a supported line receives fixes, so reproduce against
14+
it before reporting. If your project depends on `mcp` and is not yet ready for
15+
2.x, keep a `<2` upper bound on your `mcp` requirement and follow the
16+
[migration guide](https://py.sdk.modelcontextprotocol.io/migration/) when you
17+
migrate.
418

519
## Reporting Security Issues
620

7-
This SDK is maintained by [Anthropic](https://www.anthropic.com/) as part of the Model Context Protocol project.
21+
If you discover a security vulnerability in this repository, please report it through
22+
the [GitHub Security Advisory process](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability)
23+
for this repository.
824

9-
The security of our systems and user data is Anthropic’s top priority. We appreciate the work of security researchers acting in good faith in identifying and reporting potential vulnerabilities.
25+
Please **do not** report security vulnerabilities through public GitHub issues, discussions,
26+
or pull requests.
1027

11-
Our security program is managed on HackerOne and we ask that any validated vulnerability in this functionality be reported through their [submission form](https://hackerone.com/anthropic-vdp/reports/new?type=team&report_type=vulnerability).
28+
## What to Include
1229

13-
## Vulnerability Disclosure Program
30+
To help us triage and respond quickly, please include:
1431

15-
Our Vulnerability Program Guidelines are defined on our [HackerOne program page](https://hackerone.com/anthropic-vdp).
32+
- A description of the vulnerability
33+
- Steps to reproduce the issue
34+
- The potential impact
35+
- Any suggested fixes (optional)

0 commit comments

Comments
 (0)