Skip to content

Security: CoreTrace/coretrace

Security

SECURITY.md

Security Policy

Reporting A Vulnerability

Do not open a public issue for vulnerabilities that could expose users, partners, or private code.

Report privately to the current maintainer:

  • Maintainer: Hugo Payet
  • Contact: replace this line with the private security email before publishing the repository broadly.

Include:

  • affected commit, tag, or binary version;
  • reproduction steps;
  • input files or sanitized proof of concept;
  • expected and observed behavior;
  • impact assessment if known.

Response Targets

Step Target
Acknowledge report 5 business days
Initial triage 10 business days
Remediation plan After triage, based on severity
Public disclosure After fix or coordinated disclosure agreement

Supported Versions

The project is currently pre-1.0. Security fixes are handled on the active development branch and latest release artifacts.

Sensitive Material

Security reports, unpublished analyzer rules, model internals, partner findings, and proof-of-concept inputs are controlled or restricted material. Do not publish them before triage and approval.

There aren't any published security advisories