# Security Policy
## Reporting Security Vulnerabilities
If you discover a security vulnerability in this project, please report it by creating a **private security advisory** on GitHub:
1. Go to the [Security tab](https://github.com/brianirish/laravel-mcp-companion/security) of this repository
2. Click "Report a vulnerability"
3. Provide details about the vulnerability
This will create a private discussion that only you and I can see until we decide how to handle it.
For non-security bugs, please use the regular [issue tracker](https://github.com/brianirish/laravel-mcp-companion/issues).
## Scope
This project is a Model Context Protocol (MCP) server for Laravel documentation. Security concerns mainly involve:
- Documentation parsing and serving
- Network communication
- Dependency vulnerabilities
## What to Expect
As this is a personal project maintained in my spare time, please expect:
- Response within 1-2 weeks for initial acknowledgment
- Best-effort fixes depending on severity and complexity
- Open communication about timeline and feasibility
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/brianirish/laravel-docs-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server