Report privately via GitHub Security Advisory: https://github.com/tracecoreai/tracecore/security/advisories/new. Do not open a public issue.
Include: description + impact, reproduction steps, affected versions, any suggested mitigation.
- Synthesis-engine (proprietary) vulnerabilities: file a separate private advisory at the same URL, tag it
synthesis-engine.
- Acknowledgement within 2 business days
- Coordinated disclosure with a default 90-day embargo, extendable by mutual agreement
- A CVE will be requested for any vulnerability that affects deployed users
- If you have not heard back within 7 days, ping the advisory thread — the 2-day ack SLA is monitored but escalation-on-silence is a documented branch.
In scope: the tracecore binary and code in this repository, the Helm chart / manifests / Dockerfiles published from it, and documented supported configuration.
Out of scope: third-party dependencies (report upstream) and modified customer deployments.
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, report privately, and give us reasonable time before public disclosure.