Security fixes are applied to the latest release line. Report issues against the current main branch and identify the published package version or commit you tested.
Do not open a public GitHub issue for a suspected vulnerability. Do not include tokens, credentials, private endpoints, customer data, or exploit details in public discussions, pull requests, or logs.
Private vulnerability reporting is not configured yet for this repository. Until maintainers enable GitHub's Report a vulnerability control or publish a monitored private contact, there is no supported channel for submitting sensitive exploit details. Do not disclose those details publicly.
Maintainers must configure a private reporting channel before accepting private reports or making an acknowledgement-time commitment. After a channel is published, this policy will state the required report content, acknowledgement target, coordinated-disclosure process, and optional reporter credit.
Report vulnerabilities in this repository, published @theorvane/type-mcp artifacts, CI workflows, and documented release/supply-chain paths. Application-specific handler bugs, credentials committed by another project, or unsupported integrations may be out of scope, but reports will be triaged in good faith.