If you believe you've found a security vulnerability in acp-traces, please report it responsibly.
Do not open a public GitHub issue for security-sensitive bugs.
Instead:
- Email the maintainers (preferred): you can reach the project owner via the email listed in the commit history or on their GitHub profile.
- Private security advisory on GitHub: go to Security → Advisories and click Report a vulnerability to create a private draft. This keeps the discussion confidential until a fix is ready.
Include:
- A short description of the issue
- Steps to reproduce
- Impact (e.g., data exposure, denial of service)
- Suggested fix if you have one (optional)
We will acknowledge receipt and aim to respond with an initial assessment within a few days. We may ask for more details. Once a fix is released, we can coordinate on disclosure timing (e.g., release notes, CVE) and credit you if you wish.
We generally support the latest release with security fixes. If you need a patch for an older version, say so in your report.
- Fixes are developed in private and merged when ready.
- A new patch release is published (e.g., 0.3.1).
- Release notes and/or a security advisory will describe the issue and the fix after users have had time to upgrade.
Thank you for helping keep acp-traces and its users safe.