From 33cab58885a2fe68658ae755615f3e2ef96de8cd Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 20:39:54 +0000 Subject: [PATCH] [v1.x] Point SECURITY.md at GitHub Security Advisories Backport the security policy from main to v1.x. The HackerOne program this file referenced is no longer in use; vulnerability reports for this repository go through GitHub private vulnerability reporting. --- SECURITY.md | 32 ++++++++++++++++++++++++++------ 1 file changed, 26 insertions(+), 6 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 6545156105..5a69875124 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,15 +1,35 @@ # Security Policy -Thank you for helping us keep the SDKs and systems they interact with secure. +Thank you for helping keep the Model Context Protocol and its ecosystem secure. + +## Supported Versions + +| Version | Line | Support | +| ---------------------------------------- | ----------------------- | ------------------------------------------- | +| 2.x (newest release) | current stable (`main`) | bug fixes, security fixes, new features | +| 1.x newest release (`v1.x` branch) | maintenance | critical bug fixes and security fixes | +| older 1.x releases, and all pre-releases | unsupported | upgrade to the newest 1.x release or to 2.x | + +Only the newest release of a supported line receives fixes, so reproduce against +it before reporting. If your project depends on `mcp` and is not yet ready for +2.x, keep a `<2` upper bound on your `mcp` requirement and follow the +[migration guide](https://py.sdk.modelcontextprotocol.io/migration/) when you +migrate. ## Reporting Security Issues -This SDK is maintained by [Anthropic](https://www.anthropic.com/) as part of the Model Context Protocol project. +If you discover a security vulnerability in this repository, please report it through +the [GitHub Security Advisory process](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability) +for this repository. -The security of our systems and user data is Anthropic’s top priority. We appreciate the work of security researchers acting in good faith in identifying and reporting potential vulnerabilities. +Please **do not** report security vulnerabilities through public GitHub issues, discussions, +or pull requests. -Our security program is managed on HackerOne and we ask that any validated vulnerability in this functionality be reported through their [submission form](https://hackerone.com/anthropic-vdp/reports/new?type=team&report_type=vulnerability). +## What to Include -## Vulnerability Disclosure Program +To help us triage and respond quickly, please include: -Our Vulnerability Program Guidelines are defined on our [HackerOne program page](https://hackerone.com/anthropic-vdp). +- A description of the vulnerability +- Steps to reproduce the issue +- The potential impact +- Any suggested fixes (optional)