Please do not open a public GitHub issue for security vulnerabilities.
Report them via GitHub's private vulnerability reporting.
Include:
- A description of the vulnerability and its potential impact
- Steps to reproduce
- Any suggested fixes if you have them
You will receive a response within 5 business days.
devtrace reads local files (Claude/Codex session logs) and calls the GitHub API
via the gh CLI using your existing authentication. It does not transmit any
data to external servers beyond GitHub's API and the optionally configured
Jira/Tempo APIs.
Credentials (Jira API token, Tempo API token) are stored in the OS keychain
(Windows Credential Manager on Windows, macOS Keychain on macOS, libsecret on Linux)
via the keyring library — never in plain text on disk.