Skip to content

Security: Excoriate/mcp-terragrunt-docs

SECURITY.md

Security Policy

Project Scope

This repository implements a Model Context Protocol (MCP) server in Deno/TypeScript, providing contextual information and tools for Terragrunt documentation and GitHub issues. It is intended for use by AI agents, IDE integrations, and developers working with Terragrunt.

Supported Versions

  • Only the main branch is officially supported. Please report vulnerabilities found in the latest code on this branch.

Reporting a Vulnerability

If you discover a security vulnerability in this project, please do not create a public GitHub issue. Instead, follow these steps:

  1. Preferred: Open a private security advisory on GitHub (recommended for confidential reporting).
  2. Alternative: Email the maintainer at [[email protected]] with details of the vulnerability.

We will respond as quickly as possible and coordinate a fix and disclosure process.

Responsible Disclosure

  • Please provide as much detail as possible to help us understand and reproduce the issue.
  • We ask that you give us a reasonable amount of time to address the vulnerability before any public disclosure.
  • We are committed to transparent and responsible handling of all security reports.

Exclusions

  • This policy does not cover vulnerabilities in third-party dependencies (report those upstream).
  • Do not use automated tools to perform denial-of-service or destructive testing.

Further Reading


Thank you for helping keep this project and its users secure!

There aren’t any published security advisories