Skip to content

Security: yakubilik/DevTrace

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Report them via GitHub's private vulnerability reporting.

Include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce
  • Any suggested fixes if you have them

You will receive a response within 5 business days.

Scope

devtrace reads local files (Claude/Codex session logs) and calls the GitHub API via the gh CLI using your existing authentication. It does not transmit any data to external servers beyond GitHub's API and the optionally configured Jira/Tempo APIs.

Credentials (Jira API token, Tempo API token) are stored in the OS keychain (Windows Credential Manager on Windows, macOS Keychain on macOS, libsecret on Linux) via the keyring library — never in plain text on disk.

There aren't any published security advisories