We are very grateful for any security reports and see them as a valuable way to improve the quality and reliability of our codebase. As a non-profit open-source project, we appreciate the time and effort the community puts into helping us keep OpenFastTrace secure.
Please note that we do not offer bug bounties.
To report a vulnerability, please use the GitHub Security Advisory reporting feature or contact the maintainers directly. We strive to address all security concerns in a timely and professional manner.
To enhance transparency and security, SPDX SBOMs (Software Bill of Materials) are included with the plugin releases starting from version 2.4.0. These files provide a comprehensive list of all components and dependencies used in the project.