Security fixes are applied to the latest released version of Rootly MCP Server
and the current main branch. Please reproduce a suspected vulnerability
against the latest version before reporting it when possible.
Do not report security vulnerabilities through public GitHub issues.
Email security@rootly.com with:
- a description of the vulnerability and its potential impact;
- the affected version, commit, or deployment mode;
- clear reproduction steps or a proof of concept; and
- any suggested remediation, if available.
Follow Rootly's Vulnerability Disclosure Policy for reporting guidelines and safe-harbor terms.