|
1 | 1 | # Security Policy |
2 | 2 |
|
3 | | -Thank you for helping us keep the SDKs and systems they interact with secure. |
| 3 | +Thank you for helping keep the Model Context Protocol and its ecosystem secure. |
| 4 | + |
| 5 | +## Supported Versions |
| 6 | + |
| 7 | +| Version | Line | Support | |
| 8 | +| ---------------------------------------- | ----------------------- | ------------------------------------------- | |
| 9 | +| 2.x (newest release) | current stable (`main`) | bug fixes, security fixes, new features | |
| 10 | +| 1.x newest release (`v1.x` branch) | maintenance | critical bug fixes and security fixes | |
| 11 | +| older 1.x releases, and all pre-releases | unsupported | upgrade to the newest 1.x release or to 2.x | |
| 12 | + |
| 13 | +Only the newest release of a supported line receives fixes, so reproduce against |
| 14 | +it before reporting. If your project depends on `mcp` and is not yet ready for |
| 15 | +2.x, keep a `<2` upper bound on your `mcp` requirement and follow the |
| 16 | +[migration guide](https://py.sdk.modelcontextprotocol.io/migration/) when you |
| 17 | +migrate. |
4 | 18 |
|
5 | 19 | ## Reporting Security Issues |
6 | 20 |
|
7 | | -This SDK is maintained by [Anthropic](https://www.anthropic.com/) as part of the Model Context Protocol project. |
| 21 | +If you discover a security vulnerability in this repository, please report it through |
| 22 | +the [GitHub Security Advisory process](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability) |
| 23 | +for this repository. |
8 | 24 |
|
9 | | -The security of our systems and user data is Anthropic’s top priority. We appreciate the work of security researchers acting in good faith in identifying and reporting potential vulnerabilities. |
| 25 | +Please **do not** report security vulnerabilities through public GitHub issues, discussions, |
| 26 | +or pull requests. |
10 | 27 |
|
11 | | -Our security program is managed on HackerOne and we ask that any validated vulnerability in this functionality be reported through their [submission form](https://hackerone.com/anthropic-vdp/reports/new?type=team&report_type=vulnerability). |
| 28 | +## What to Include |
12 | 29 |
|
13 | | -## Vulnerability Disclosure Program |
| 30 | +To help us triage and respond quickly, please include: |
14 | 31 |
|
15 | | -Our Vulnerability Program Guidelines are defined on our [HackerOne program page](https://hackerone.com/anthropic-vdp). |
| 32 | +- A description of the vulnerability |
| 33 | +- Steps to reproduce the issue |
| 34 | +- The potential impact |
| 35 | +- Any suggested fixes (optional) |
0 commit comments