Security

Reporting a vulnerability

Email [email protected] with:

Response within 48h. Fix within 14 days for P0/P1, 30 days for P2/P3.

Disclosure timeline

  1. T+0: Report received
  2. T+48h: Acknowledgement + triage
  3. T+14d: Patch for P0/P1 (CVE assigned)
  4. T+30d: Public disclosure + advisory
  5. T+90d: Hall of fame

OpenSSF Best Practices

All 340+ MEOK MCP packages are enrolled in the OpenSSF Best Practices self-attestation program. Target tier: silver. Coverage: 99.4% license, 98.8% SECURITY.md, 98.2% CI, 34.9% dependabot, 34.9% CodeQL, 38.1% Scorecard workflow.

Signed releases

All wheels are published with PyPI SHA-256 hashes (PEP 740). For higher assurance, Sigstore cosign signatures are available for the 14/14 Apify actors and 3/341 PyPI packages (work in progress: cosign-sign.yaml in 130/341 workflows).

SLSA provenance

All builds use GitHub Actions with pinned actions. SLSA Level 3 provenance is generated automatically for all releases (cyclonedx-py SBOM + pypi-publish workflow).

Bug bounty

Coming soon — enterprise tier customers get pre-disclosure on advisories. Independent bounty program planned for 2027.

security.txt

RFC 9116 compliant security.txt at /.well-known/security.txt.