Security is important to FCODE TraceHub because the platform processes application telemetry and may receive sensitive operational data.
FCODE TraceHub is currently in early development and has no stable production release.
| Version | Supported |
|---|---|
| Development branch | Yes |
| Pre-release builds | Best effort |
| Stable release | Not released |
Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Use GitHub private vulnerability reporting:
- Open the repository's Security section.
- Select Report a vulnerability.
- Include the affected component, reproduction details, impact, and suggested remediation when available.
Do not include real credentials, API keys, access tokens, or personal data in the report.
The maintainers will attempt to:
- Acknowledge the report
- Review and reproduce the issue
- Assess its impact
- Prepare a fix when confirmed
- Coordinate disclosure after remediation
Response times may vary while the project is maintained on a best-effort basis.
Security-sensitive areas include:
- API key generation, storage, and verification
- Authentication and authorization
- Tenant and project isolation
- Telemetry ingestion
- Sensitive-data redaction
- Dependency vulnerabilities
- Container and deployment configuration
Please allow maintainers reasonable time to investigate and address a confirmed vulnerability before public disclosure.