We value the work of security researchers and users who help us keep OpenFastTrace secure. Thank you for your support!
We provide security updates for the latest major version. For a detailed overview of supported versions and End-of-Life (EoL) dates, please see our Project Lifecycle.
If you discover a potential security issue, please report it privately via GitHub Security Advisories. We follow coordinated disclosure and aim to:
- Respond to your report within 48 hours.
- Provide a fix within 30 days.
- Disclose the details publicly once a fix is available and users have had time to update.
While we don't offer bug bounties, we'd be happy to publicly acknowledge your contribution in the advisory.
Starting with version 4.10.0, each GitHub release includes an SPDX Software Bill of Materials (SBOM) for the OpenFastTrace product JAR and a SHA-256 checksum for the SBOM.