Skip to content

Security: itsallcode/itsallcode-apt-repository

Security

SECURITY.md

Security Policy

We value the work of security researchers and users who help us keep the OpenFastTrace Debian package secure. Thank you for your support!

Supported Versions

We provide security updates for the latest package release. Security fixes to OpenFastTrace itself follow the upstream project lifecycle.

Reporting a Vulnerability

If you discover a potential security issue in this packaging repository or its published packages, please report it privately via GitHub Security Advisories. For a vulnerability in OpenFastTrace itself, use the upstream security reporting channel.

We follow coordinated disclosure and aim to:

  • Respond to your report within 48 hours.
  • Provide a fix within 30 days.
  • Disclose the details publicly once a fix is available and users have had time to update.

While we don't offer bug bounties, we'd be happy to publicly acknowledge your contribution in the advisory.

There aren't any published security advisories