Skip to content

Security: shacharsol/js-package-manager-mcp

Security

SECURITY.md

Security Policy

Production Infrastructure Protection

πŸ”’ Hosted Service Security

The production service at https://api.npmplus.dev/mcp is protected infrastructure:

  • Only maintainers can deploy to production
  • Automatic deployments are disabled for security
  • Contributors cannot trigger production builds
  • Manual deployment verification ensures stability

πŸ›‘οΈ For Contributors

When contributing to this project:

  • βœ… Your changes will be reviewed before any production deployment
  • βœ… You can test locally using the self-deployment guide
  • βœ… CI/CD tests ensure code quality without production access
  • βœ… Your contributions are valued and will be properly credited

🏒 For Enterprise Users

For production enterprise deployments:

  • Deploy your own instance using the deployment guide
  • Control your own infrastructure and security policies
  • Customize as needed for your environment
  • Full ownership of your deployment and data

Reporting Security Issues

If you discover a security vulnerability:

  1. Do NOT open a public issue
  2. Email directly to: [email protected]
  3. Include details about the vulnerability
  4. We will respond within 24 hours

Security Best Practices

When self-deploying:

  • βœ… Use environment variables for sensitive configuration
  • βœ… Enable HTTPS for all endpoints
  • βœ… Set up rate limiting for production use
  • βœ… Monitor access logs and usage patterns
  • βœ… Keep dependencies updated regularly

Supported Versions

Version Supported
1.0.x βœ… Yes
< 1.0 ❌ No

Only the latest version receives security updates.

There aren’t any published security advisories