# π‘οΈ Security Policy
## π Supported Versions
We aim to keep `CodeGraphContext` up to date and secure. Please see below for the versions we currently support with security updates.
| Version | Supported |
|---------|--------------------|
| Latest | β Yes |
| Older | β No |
---
## π¬ Reporting a Vulnerability
If you discover a security vulnerability, **please do not open an issue** on GitHub.
Instead, follow these steps:
1. **Email the maintainer directly**
2. Include the following details:
- Description of the vulnerability
- Steps to reproduce (if possible)
- Potential impact
- Any mitigation or workaround suggestions
β We aim to respond to security reports **within 72 hours**.
---
## π« Responsible Disclosure Guidelines
We ask that you:
- Do not publicly disclose the issue until it has been resolved.
- Avoid testing vulnerabilities in a way that could disrupt services.
- Act in good faith and with respect for user data and privacy.
---
## π Disclosure Policy
- We follow a **coordinated disclosure** approach.
- We appreciate responsible reporting and will publicly disclose the issue only **after a fix has been released**.
---
## β Security Best Practices
While using this project, we recommend you:
- Always run software in a secure and isolated environment.
- Keep your dependencies up to date.
- Avoid sharing sensitive API keys or credentials in `.env` or other public files.
---
## π Acknowledgments
We value the contributions from the community and encourage responsible disclosure to help keep `CodeGraphContext` safe and secure for all users.
---
## π Resources
- [GitHub Security Advisories](https://docs.github.com/en/code-security/security-advisories)
- [OpenSSF Best Practices](https://bestpractices.dev/)
- [OWASP Top 10](https://owasp.org/www-project-top-ten/)
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Shashankss1205/CodeGraphContext'
If you have feedback or need assistance with the MCP directory API, please join our Discord server