This policy covers:
- The
codebahnCLI binary and its source in this repository. - The hosted MCP endpoint at
https://codebahn.net/mcp.
Please report security issues to security@codebahn.net. Do not open a public GitHub issue for security reports.
Include as much detail as you can: affected version or commit, steps to reproduce, and potential impact. We will acknowledge your report and work with you on a fix and coordinated disclosure timeline.
Full details on our vulnerability disclosure process, scope, and safe harbor are published at https://codebahn.net/security.