# Security Policy
## Supported versions
Security fixes are made on the latest released version of mcp-proxy. Older
releases are not maintained separately.
## Reporting a vulnerability
Please report suspected vulnerabilities through a
[private GitHub security advisory](https://github.com/joshrotenberg/mcp-proxy/security/advisories/new).
Do not open a public issue for a vulnerability that has not been disclosed.
Include the affected version, a minimal reproduction, the expected impact, and
any suggested mitigation. You should receive an acknowledgement within seven
days. Once a fix is available, the advisory will be coordinated with a release.
For dependency vulnerabilities, include the relevant RustSec advisory when one
exists.