Email [email protected] with:
Response within 48h. Fix within 14 days for P0/P1, 30 days for P2/P3.
All 340+ MEOK MCP packages are enrolled in the OpenSSF Best Practices self-attestation program. Target tier: silver. Coverage: 99.4% license, 98.8% SECURITY.md, 98.2% CI, 34.9% dependabot, 34.9% CodeQL, 38.1% Scorecard workflow.
All wheels are published with PyPI SHA-256 hashes (PEP 740). For higher assurance, Sigstore cosign signatures are available for the 14/14 Apify actors and 3/341 PyPI packages (work in progress: cosign-sign.yaml in 130/341 workflows).
All builds use GitHub Actions with pinned actions. SLSA Level 3 provenance is generated automatically for all releases (cyclonedx-py SBOM + pypi-publish workflow).
Coming soon — enterprise tier customers get pre-disclosure on advisories. Independent bounty program planned for 2027.
RFC 9116 compliant security.txt at /.well-known/security.txt.