Files
modelcontextprotocol--pytho…/SECURITY.md
T
Max 6f69a3758e
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
Deploy Docs / deploy-docs (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
Present v2 as the stable release across the README, docs, and policies (#3178)
2026-07-28 14:31:36 +01:00

1.6 KiB

Security Policy

Thank you for helping keep the Model Context Protocol and its ecosystem secure.

Supported Versions

Version Line Support
2.x (newest release) current stable (main) bug fixes, security fixes, new features
1.28.x (v1.x branch) maintenance critical bug fixes and security fixes
< 1.28, and all pre-release versions unsupported upgrade to the newest 1.28.x or to 2.x

Only the newest release of a supported line receives fixes, so reproduce against it before reporting. If your project depends on mcp and is not yet ready for 2.x, constrain to mcp>=1.28,<2 and follow the migration guide when you migrate.

Reporting Security Issues

If you discover a security vulnerability in this repository, please report it through the GitHub Security Advisory process for this repository.

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

What to Include

To help us triage and respond quickly, please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact
  • Any suggested fixes (optional)