We value the work of security researchers and users who help us keep the OpenFastTrace Debian package secure. Thank you for your support!
We provide security updates for the latest package release. Security fixes to OpenFastTrace itself follow the upstream project lifecycle.
If you discover a potential security issue in this packaging repository or its published packages, please report it privately via GitHub Security Advisories. For a vulnerability in OpenFastTrace itself, use the upstream security reporting channel.
We follow coordinated disclosure and aim to:
- Respond to your report within 48 hours.
- Provide a fix within 30 days.
- Disclose the details publicly once a fix is available and users have had time to update.
While we don't offer bug bounties, we'd be happy to publicly acknowledge your contribution in the advisory.