Vericore

Security Policy

Supported versions

Version Supported
0.8.x Yes — current Vericore release line
0.7.x Limited; upgrade to Vericore 0.8.2 recommended
0.6.x and older No

Reporting a vulnerability

Do not disclose security vulnerabilities in a public issue. Report them privately to shivanshsoni568@gmail.com with:

Do not include API keys, credentials, private source code, or personal data unless absolutely necessary.

The project aims to acknowledge reports within 48 hours and provide an initial assessment within seven days. Fix and disclosure timelines depend on severity, reproducibility, and release risk.

Security model

Vericore is designed primarily for local analysis:

The REST server does not provide authentication, tenant isolation, report authorization, TLS termination, report expiration, or a complete public-internet deployment boundary. The MCP stdio server also assumes a trusted local caller. Add those controls before exposing it outside a trusted local or internal network.

Agentic security boundary

Autonomous code modification is not a current default capability. Before any agent can modify a repository, Vericore should enforce:

A model’s confidence must never substitute for an authorization or verification decision.

Deployment guidance

Contact

Security reports: shivanshsoni568@gmail.com