Skip to content

Security: Excoriate/mcp-terraform-aws-provider-docs

Security

SECURITY.md

Security Policy

Project Scope

This repository implements a Model Context Protocol (MCP) server in Deno/TypeScript, providing contextual information and tools for AWS provider documentation for Terragrunt and GitHub issues. It is intended for use by AI agents, IDE integrations, and developers working with Terragrunt.

Supported Versions

  • Only the main branch is officially supported. Please report vulnerabilities found in the latest code on this branch.

Reporting a Vulnerability

If you discover a security vulnerability in this project, please do not create a public GitHub issue. Instead, follow these steps:

  1. Preferred: Open a private security advisory on GitHub (recommended for confidential reporting).
  2. Alternative: Email the maintainer at [[email protected]] with details of the vulnerability.

We will respond as quickly as possible and coordinate a fix and disclosure process.

Responsible Disclosure

  • Please provide as much detail as possible to help us understand and reproduce the issue.
  • We ask that you give us a reasonable amount of time to address the vulnerability before any public disclosure.
  • We are committed to transparent and responsible handling of all security reports.

Exclusions

  • This policy does not cover vulnerabilities in third-party dependencies (report those upstream).
  • Do not use automated tools to perform denial-of-service or destructive testing.

Further Reading


Thank you for helping keep this project and its users secure!

There aren’t any published security advisories