Skip to content

Security: cockroachdb/cockroachdb-mcp-server

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not file public GitHub issues for security problems.

Report suspected vulnerabilities privately via either of:

Please include enough detail to reproduce the issue (version or commit SHA, configuration, steps, and impact).

You can expect an initial acknowledgement within two business days. We will keep you updated as we investigate and remediate.

Supported versions

This project is pre-1.0. Only the latest tagged release receives security fixes. Once a 1.x line is established, this section will be updated with the supported version matrix.

Coordinated disclosure

We follow a coordinated-disclosure model. After a fix is released and users have had time to upgrade, we publish a GitHub Security Advisory describing the issue, affected versions, and credit to the reporter.

There aren't any published security advisories