Skip to content

Security: useward/ward

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Ward, please report it responsibly.

Do NOT open a public issue for security vulnerabilities.

Instead, please email security concerns to the project maintainers directly.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

Response Timeline

  • We will acknowledge receipt within 48 hours
  • We will provide a detailed response within 7 days
  • We will work with you to understand and resolve the issue

Scope

This security policy applies to:

  • @useward/instrumentation (Next.js instrumentation SDK)
  • @useward/mcp (MCP server)
  • @useward/devtools (Local development dashboard)

Security Best Practices

When using Ward:

  • Only run devtools in development environments
  • Do not expose devtools port (19393) to public networks
  • Keep dependencies updated

Thank you for helping keep Ward secure.

There aren’t any published security advisories