Security fixes target the latest released version of Tracker. Older versions may not receive backports.
Do not report suspected vulnerabilities through public issues, discussions, or pull requests.
Use GitHub's private vulnerability reporting for this repository:
https://github.com/rightxt/tracker/security/advisories/new
Include, when possible:
- the affected Tracker package, site component, or repository workflow;
- the affected version or commit;
- reproduction steps or a proof of concept;
- the expected security impact;
- relevant environment details.
Keep exploit details private until the issue has been investigated and any necessary fix has been coordinated.
Reports may cover runtime code, the site, packaging, supply-chain risks, or repository automation. Relevant examples include:
- Tracker packages and their public browser/runtime behavior;
- the project website, demos, and tools when they create a security impact;
- package contents, exports, installation, or dependency behavior;
- npm publication, provenance, dependency confusion, or other supply-chain risks;
- repository automation or release infrastructure that could affect published artifacts or project integrity.
Use issues or Discussions for non-security bugs, feature requests, and usage questions.