Skip to content

Security: perforce/p4mcp-server

Security

SECURITY.md

Security Policy

The P4MCP Server interacts with Perforce servers and may handle credentials and workspace configurations.

Security is important to us. If you discover a security vulnerability, please report it responsibly.


Reporting a Vulnerability

Please do not open a public issue for security vulnerabilities.

Instead:

  1. Use GitHub Security Advisories (if enabled), or
  2. Contact the maintainers privately via the repository maintainers, or
  3. Report via our dedicated support email for vulnerabilities

Include the following information:

  • A description of the vulnerability
  • Steps to reproduce (if applicable)
  • Its potential impact
  • Suggested mitigation (if known)

Please remove any sensitive credentials before sharing logs.


What Qualifies as a Security Issue?

Examples include:

  • Credential exposure or leakage
  • Unsafe default behavior that allows unintended destructive operations
  • Improper permission handling
  • Injection vulnerabilities in command execution
  • Privilege escalation scenarios

If you are unsure whether something qualifies as a security issue, report it privately.


Thank you for helping keep P4MCP Server secure.

There aren't any published security advisories