Skip to main content
Glama
boecht

BitSight Community MCP Server

by boecht
SECURITY.md1.12 kB
# Security Policy ## Supported Versions - Only the most recent **stable release** (currently v4.0.0) receives security updates. - Older tags are considered end-of-life. - Pre-release builds (alpha, beta, RC) are **not** covered; use them at your own risk. ## Reporting a Vulnerability Report privately via [GitHub Security Advisories](https://github.com/boecht/birre/security/advisories). Please include reproduction steps, expected vs. actual behaviour, logs, and any mitigating context. We aim to acknowledge new reports within **five business days** and will keep you informed throughout triage and remediation. ## Release Verification & Supply Chain BiRRe releases ship with: - Sigstore signing (Fulcio + Rekor) for artifacts and GitHub releases. - Software Bills of Materials (SBOMs) and dependency review logs. - Trusted publisher deployment to PyPI (artifact hashes match GitHub releases). Follow [docs/SECURITY_VERIFICATION.md](docs/SECURITY_VERIFICATION.md) to verify downloaded artifacts and PyPI installations. If you detect tampering, contact the maintainers via Security Advisories immediately.

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/boecht/bitsight-community-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server