Skip to content

Security: TraceCoreAI/tracecore

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Report privately via GitHub Security Advisory: https://github.com/tracecoreai/tracecore/security/advisories/new. Do not open a public issue.

Include: description + impact, reproduction steps, affected versions, any suggested mitigation.

  • Synthesis-engine (proprietary) vulnerabilities: file a separate private advisory at the same URL, tag it synthesis-engine.

What to expect

  • Acknowledgement within 2 business days
  • Coordinated disclosure with a default 90-day embargo, extendable by mutual agreement
  • A CVE will be requested for any vulnerability that affects deployed users
  • If you have not heard back within 7 days, ping the advisory thread — the 2-day ack SLA is monitored but escalation-on-silence is a documented branch.

Scope

In scope: the tracecore binary and code in this repository, the Helm chart / manifests / Dockerfiles published from it, and documented supported configuration.

Out of scope: third-party dependencies (report upstream) and modified customer deployments.

Safe harbor

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, report privately, and give us reasonable time before public disclosure.

There aren't any published security advisories