Responsible Disclosure Policy
Responsible Disclosure Policy
Last updated: February 22, 2026
Reporting Security Vulnerabilities in BugTraceAI
We take the security of BugTraceAI seriously. If you discover a security vulnerability in the BugTraceAI software itself, we ask that you follow responsible disclosure practices.
How to Report
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please use one of the following methods:
-
GitHub Security Advisories (preferred): Report the vulnerability through the GitHub Security Advisories feature on the BugTraceAI-CLI repository: https://github.com/BugTraceAI/BugTraceAI-CLI/security/policy
-
Direct contact: Reach out privately via X/Twitter: @yz9yt
What to Include
When reporting a vulnerability, please provide:
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue.
- The version of BugTraceAI affected.
- Any relevant logs, screenshots, or proof-of-concept code.
Response Timeline
- Acknowledgment: We aim to acknowledge your report within 48 hours.
- Assessment: We will assess the severity and validity of the report and keep you informed of our progress.
- Fix: We will work to address confirmed vulnerabilities promptly and coordinate disclosure with you.
Our Commitments
- We will not take legal action against researchers who report vulnerabilities in good faith and follow this policy.
- We will credit reporters in release notes (unless you prefer to remain anonymous).
- We will work transparently to resolve confirmed issues.
Scope
This policy applies to vulnerabilities in:
- The BugTraceAI-CLI tool
- The BugTraceAI-WEB interface
- The BugTraceAI parent repository and related infrastructure
For security issues in third-party dependencies, please report them to the respective maintainers.
Contact
- X/Twitter: @yz9yt
- GitHub Security Advisories: BugTraceAI-CLI Security Policy