Skip to content

Security: brianirish/laravel-mcp-companion

SECURITY.md

Security Policy

Reporting Security Vulnerabilities

If you discover a security vulnerability in this project, please report it by creating a private security advisory on GitHub:

  1. Go to the Security tab of this repository
  2. Click "Report a vulnerability"
  3. Provide details about the vulnerability

This will create a private discussion that only you and I can see until we decide how to handle it.

For non-security bugs, please use the regular issue tracker.

Scope

This project is a Model Context Protocol (MCP) server for Laravel documentation. Security concerns mainly involve:

  • Documentation parsing and serving
  • Network communication
  • Dependency vulnerabilities

What to Expect

As this is a personal project maintained in my spare time, please expect:

  • Response within 1-2 weeks for initial acknowledgment
  • Best-effort fixes depending on severity and complexity
  • Open communication about timeline and feasibility

There aren’t any published security advisories