Skip to content

Security: Zexylz/mcmm

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of the MCMM plugin are currently supported with security updates:

Version Supported
latest
< 1.0.0

Reporting a Vulnerability

We take the security of this project seriously. If you believe you have found a security vulnerability, please do NOT open a public issue. Instead, please report it via one of the following methods:

  1. GitHub Security Advisory: Use the "Report a vulnerability" button in the "Security" tab of this repository. This is the preferred method as it allows for private discussion and coordinated disclosure.
  2. Private Contact: If you cannot use GitHub's reporting tool, please reach out to the repository maintainers through their profile contact information.

What to include in your report

To help us address the issue quickly, please include:

  • A descriptive title.
  • Clear steps to reproduce the vulnerability (PoC).
  • Potential impact if the vulnerability is exploited.
  • Any suggested mitigations.

Response Process

After receiving a report, we will:

  1. Acknowledge receipt within 48-72 hours.
  2. Investigate the issue and confirm the vulnerability.
  3. Work on a fix and test it.
  4. Issue a new release with the security fix.
  5. Provide credit to the reporter (unless they wish to remain anonymous).

Ground Rules

  • Coordinate disclosure: Give us a reasonable amount of time to fix the issue before sharing it publicly.
  • No disruptive testing: Do not perform tests that could degrade the service or impact other users.
  • Privacy: Do not attempt to access or leak user data.

Thank you for helping keep MCMM secure!

There aren't any published security advisories