| Version | Supported |
|---|---|
| 0.1.x | Yes |
If you discover a security vulnerability in satellite-mcp, please report it responsibly.
Email: contact@orhanyildirim.us
Do NOT open a public GitHub issue for security vulnerabilities.
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue.
- Any relevant logs, screenshots, or proof-of-concept code.
- You will receive an acknowledgment within 48 hours of your report.
- We will work with you to understand the issue and determine a fix timeline.
- Once resolved, we will coordinate disclosure with you before publishing any advisory.
This security policy covers the satellite-mcp codebase only. It does not cover:
- Third-party APIs that satellite-mcp connects to (Sentinel Hub, NASA, OpenSky, MarineTraffic, ACLED, etc.)
- Vulnerabilities in upstream dependencies (report those to the respective maintainers)
- Misconfiguration of API keys or environment variables by end users