Skip to content

Security: trakrlog-com/trakrlog

Security

SECURITY.md

Security Policy

Supported Versions

The following table shows which versions of Trakrlog are currently supported with security updates.

Version Supported
Latest (main branch)
Previous releases ⚠️ Best effort
Pre-release / dev builds

Reporting a Vulnerability

If you discover a security vulnerability in Trakrlog, please do not open a public GitHub issue.
Instead, report it privately so we can review and fix it responsibly.

Please contact us on [email protected] including:

  • A detailed description of the issue
  • Steps to reproduce
  • Any proof-of-concept code or screenshots (if applicable)
  • Suggested fixes (optional)

We aim to acknowledge all reports as fast as possible.


Disclosure Policy

Once a vulnerability is confirmed:

  1. We will privately discuss and patch the issue.
  2. A security release or patch version will be published.
  3. Public disclosure will be made only after the fix is available.

If you find an issue but are unsure whether it’s a security concern, please report it anyway — we’ll handle it appropriately.


Security Best Practices for Self-Hosting

If you self-host Trakrlog:

  • Always use the latest stable version.
  • Run behind HTTPS with valid certificates.
  • Set strong API keys and keep them secret.
  • Limit access to admin endpoints and dashboards.
  • Regularly back up your database and configuration.

Responsible Disclosure

We strongly support responsible disclosure.
Please give us adequate time to fix the issue before making it public.

Thank you for helping make Trakrlog safer for everyone. 💙

There aren’t any published security advisories