Files
mcp-nextcloud/SECURITY.md
T
Chris CoutinhoandClaude Opus 4.7 dc820aaa4c docs(security): address review feedback on PR #740
- SECURITY.md: add response SLA (5 business days / 30 days)
- bug_report.yml: scope the Docker log command to Docker installs
- question.yml: align deployment_mode catch-all wording with bug_report.yml

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 23:22:07 +02:00

31 lines
1.2 KiB
Markdown

# Security Policy
## Reporting a Vulnerability
**Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.**
### Preferred: GitHub Private Vulnerability Reporting
Use GitHub's built-in private reporting workflow:
➡️ **[Report a vulnerability](https://github.com/cbcoutinho/nextcloud-mcp-server/security/advisories/new)**
This opens a private draft security advisory visible only to the repository maintainers. You can also reach the same form from the **Security** tab → **Report a vulnerability**.
### Fallback: Email
If you cannot use GitHub's private reporting (for example, you don't have a GitHub account), email:
**security@astrolabecloud.com**
### What to include
Whichever channel you use, please include as much of the following as you can to help us triage:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof-of-concept code, if applicable)
- The version(s) of the project affected
- Any known mitigations or workarounds
We aim to acknowledge within 5 business days and provide a fix or mitigation timeline within 30 days, and will work with you on coordinated disclosure.