Skip to content

Security: koltyj/REW-mcp

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x
< 1.0

Reporting a Vulnerability

If you discover a security issue, please report it responsibly:

  1. Do not open a public GitHub issue
  2. Email the maintainer directly at [email protected] or use GitHub Security Advisories
  3. Include:
    • Description of the issue
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes (optional)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 7 days
  • Resolution target: Depends on severity

Scope

This policy applies to the rew-mcp npm package. Issues in dependencies should be reported to those projects directly.

Security Best Practices

When using this MCP server:

  • Run with least-privilege permissions
  • Keep Node.js and dependencies updated
  • Review REW API access in your environment
  • Use official releases from npm

Thank you for helping keep this project secure.

There aren't any published security advisories