Skip to content

docs(security): update supported versions for 0.9.0 - #70

Merged
blackaxgit merged 1 commit into
mainfrom
docs/security-policy-0.9
Oct 1, 2026
Merged

blackaxgit merged 1 commit into
mainfrom
docs/security-policy-0.9

Conversation

@blackaxgit

Copy link
Copy Markdown
Owner

SECURITY.md is the repo's published security policy (isSecurityPolicyEnabled: true), but its Supported Versions section was still written for the 0.6.0 pre-release. It said "0.6.x (unreleased)" was supported and that the latest tag was 0.5.6.

Changes

  • Supported Versions: 0.9.x is supported and ≤ 0.8.x is not, keeping the existing policy that only the latest minor gets fixes. It now gives the install commands (uvx blc-ssh-mcp, pip install -U blc-ssh-mcp, ghcr.io/blackaxgit/ssh-mcp:0.9) and points out that the PyPI name is blc-ssh-mcp, not the unrelated ssh-mcp. The "0.6.0 is not released yet" paragraph is gone. The ≤ 0.5.6 confinement-flaw warning stays, now stated as fixed in 0.6.0.
  • HTTP Transport: the SSH_MCP_HTTP_ALLOWED_HOSTS bullet now matches _build_transport_security. Every host wildcard (*, *:*, *.*, *.example.com) aborts startup, and only a trailing :* port wildcard is accepted.

Verification

sol 6.1 (validator-b) checked every claim: PASS.

  • 0.9.0 is the version in __init__.py, in tag v0.9.0 and on PyPI.
  • ghcr.io/blackaxgit/ssh-mcp:0.9 resolves to an amd64 + arm64 index.
  • The 0.6.0 fix matches the CHANGELOG and README.
  • The #sftp-file-transfers anchor resolves.
  • Calling _build_transport_security directly, all four wildcards raise and api.internal.example.com:* is accepted.
  • No other stale version claims remain.

Tests: 855 passed. gitleaks is clean.

@blackaxgit
blackaxgit merged commit 7d4f273 into main Oct 1, 2026
7 of 8 checks passed
@blackaxgit
blackaxgit deleted the docs/security-policy-0.9 branch October 1, 2026 03:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant