SECURITY
Security policy
Reporting a vulnerability
If you discover a security vulnerability in this project, please report it responsibly.
Do not open a public issue.
Instead, use one of the following:
GitHub Security Advisories (preferred)
Email the maintainer directly at [email protected]
Please include:
A description of the vulnerability
Steps to reproduce or a proof of concept
The impact you believe it has
You should receive an acknowledgment within 48 hours. Fixes will be released as soon as practical, and you will be credited in the release notes unless you prefer otherwise.
Scope
This policy covers the MCP Raku module and all code in this repository. It does not cover third-party dependencies, though we will coordinate with upstream maintainers if needed.
Security measures
See the Quality and roadmap section of the README for details on the security review conducted on this codebase.