Skip to content

Responsible Disclosure Policy

Responsible Disclosure Policy

Last updated: February 22, 2026

Reporting Security Vulnerabilities in BugTraceAI

We take the security of BugTraceAI seriously. If you discover a security vulnerability in the BugTraceAI software itself, we ask that you follow responsible disclosure practices.

How to Report

Do NOT open a public GitHub issue for security vulnerabilities.

Instead, please use one of the following methods:

  1. GitHub Security Advisories (preferred): Report the vulnerability through the GitHub Security Advisories feature on the BugTraceAI-CLI repository: https://github.com/BugTraceAI/BugTraceAI-CLI/security/policy

  2. Direct contact: Reach out privately via X/Twitter: @yz9yt

What to Include

When reporting a vulnerability, please provide:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce the issue.
  • The version of BugTraceAI affected.
  • Any relevant logs, screenshots, or proof-of-concept code.

Response Timeline

  • Acknowledgment: We aim to acknowledge your report within 48 hours.
  • Assessment: We will assess the severity and validity of the report and keep you informed of our progress.
  • Fix: We will work to address confirmed vulnerabilities promptly and coordinate disclosure with you.

Our Commitments

  • We will not take legal action against researchers who report vulnerabilities in good faith and follow this policy.
  • We will credit reporters in release notes (unless you prefer to remain anonymous).
  • We will work transparently to resolve confirmed issues.

Scope

This policy applies to vulnerabilities in:

  • The BugTraceAI-CLI tool
  • The BugTraceAI-WEB interface
  • The BugTraceAI parent repository and related infrastructure

For security issues in third-party dependencies, please report them to the respective maintainers.

Contact