Skip to content

Security: aiperceivable/apcore

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in apcore, please report it responsibly.

Do NOT open a public issue for security vulnerabilities.

Please use GitHub's private vulnerability reporting feature:

  1. Go to the relevant repository's Security tab
  2. Click Report a vulnerability
  3. Fill in the details

Alternatively, email: team@aiperceivable.org

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 7 days
  • Fix or mitigation: Depends on severity; critical issues targeted within 30 days

Supported Versions

Component Supported Versions
apcore spec Latest published version
apcore-python Latest release
apcore-typescript Latest release
apcore-rust Latest release
apcore-mcp-* Latest release
apcore-a2a-* Latest release
apcore-cli-* Latest release
apcore-toolkit-* Latest release

Older versions receive security fixes on a best-effort basis.

Scope

This policy covers all repositories under the aiperceivable GitHub organization that are part of the apcore standard.

Disclosure Policy

We follow coordinated disclosure:

  1. Reporter submits vulnerability privately
  2. We confirm and assess the issue
  3. We develop and test a fix
  4. We release the fix and publish an advisory
  5. Reporter is credited (unless they prefer anonymity)

There aren’t any published security advisories