The following versions of the MCMM plugin are currently supported with security updates:
| Version | Supported |
|---|---|
| latest | ✅ |
| < 1.0.0 | ❌ |
We take the security of this project seriously. If you believe you have found a security vulnerability, please do NOT open a public issue. Instead, please report it via one of the following methods:
- GitHub Security Advisory: Use the "Report a vulnerability" button in the "Security" tab of this repository. This is the preferred method as it allows for private discussion and coordinated disclosure.
- Private Contact: If you cannot use GitHub's reporting tool, please reach out to the repository maintainers through their profile contact information.
To help us address the issue quickly, please include:
- A descriptive title.
- Clear steps to reproduce the vulnerability (PoC).
- Potential impact if the vulnerability is exploited.
- Any suggested mitigations.
After receiving a report, we will:
- Acknowledge receipt within 48-72 hours.
- Investigate the issue and confirm the vulnerability.
- Work on a fix and test it.
- Issue a new release with the security fix.
- Provide credit to the reporter (unless they wish to remain anonymous).
- Coordinate disclosure: Give us a reasonable amount of time to fix the issue before sharing it publicly.
- No disruptive testing: Do not perform tests that could degrade the service or impact other users.
- Privacy: Do not attempt to access or leak user data.
Thank you for helping keep MCMM secure!