Only the latest master branch and latest tagged release are supported.
Do not open public issues for security bugs.
Report privately by email to: mcharan@es.iitr.ac.in.
Include:
- Summary of the issue
- Steps to reproduce
- Impact assessment
- Affected version/commit
- Any proof-of-concept details
- Initial acknowledgement: within 3 business days
- Triage decision: within 7 business days
- Remediation timeline: shared after triage
- Never commit files containing credentials (
.env,.env.*). - Use
.env.exampleas the template only. - Keep
GUPSHUP_REDACT_LOGS=truein non-local environments. - Rotate Gupshup credentials immediately if leaked.
This policy covers the gupshup-mcp repository, including:
- MCP server runtime
- Gateway request handling
- Logging and redaction
- Packaging and release artifacts