Security fixes are provided for the latest tagged release. Pre-release branches are supported on a best-effort basis.
Report vulnerabilities through GitHub private vulnerability reporting. Do not open a public issue with exploit details, credentials, customer data, or tokens. Include the affected version, deployment model, reproduction steps, and impact. We will acknowledge a complete report within seven days.
BlogFactory's MCP authority is intentionally limited to site-scoped content work and CMS draft delivery. Live publishing, deletion, credential reads, arbitrary provider access, and administrator tools are outside that boundary. A report showing a bypass of tenant scope, optimistic locking, draft-only delivery, secret redaction, authentication, or token scope should be treated as security-sensitive.