Traceary

Terms of use

Traceary is an archive of release notes other people wrote. This page says what the site is for, what it can get wrong, and where to go when the answer has to be right.

What this site is

Traceary collects the release notes of 36 products from the public sources their publishers maintain, and keeps every version at its own address. It is a reference. It is free to read, it has no accounts, and it asks nothing of you.

The words on a release page are the publisher’s words, reproduced without editing. Everything around them is computed from the collected data: the index, the dates, the counts, the labels, and the matches between an advisory and the release that carries its fix. How the data is collected describes that process in full.

Security information

The security page lists 643 advisories across 21 products, and a release page carries a badge when that release closes one. All of it is copied from advisories the publishers published themselves, with the identifier and the link that came with them. The severity shown is the severity its publisher assigned.

The authoritative source for a security question is the publisher. Their advisory, their security page, their announcement list. Traceary reads those sources on a schedule and then holds a copy, so a copy here can be behind the original, incomplete, or wrong in a way the original is not.

Nothing on this site says that a version is safe. An advisory missing from these pages may still exist: it may have been published without an identifier, it may belong to a product Traceary does not track, it may have been published since the last collection run, or it may not have been published at all. A product listed with no advisories is a product with no advisories that Traceary found, which is a different statement.

The fixed in link is a computed match between the versions an advisory names and the versions in the archive. 343 of 643 advisories match this way. The match is there to help you find the release, and it is not advice about what to upgrade to. Read the advisory itself before you act on it.

Traceary is not a vulnerability scanner, a compliance record or a monitoring service. It does not know what you run and it is not built to tell you whether you are exposed.

What the archive can get wrong

Collection can fail, and it does. The status page records every run source by source, so a gap can be checked rather than guessed at. A product that stops publishing a machine readable feed stops updating here, and the archive keeps whatever it already collected.

Notes longer than 40 kB are cut, and those pages say so and link to the publisher. Labels such as breaking or security are matched from words that appear in the notes, so a release that changed an API without using the word carries no label. Dates are the publisher’s dates, and a version that was retagged, withdrawn or republished can read here as it first appeared.

Using the archive

Read it, link to it, and quote it the way you would quote the original. Every product has a feed and so does the site, and the feeds carry the same entries at a fraction of what fetching pages costs both sides.

Version addresses are meant to hold. Anything already linked from somewhere else depends on them, so a change to the shape of a version address is treated here as a breaking change and recorded on the changelog.

Links out

Every page links back to the source it was collected from, and release notes carry whatever links their authors put in them. Those sites belong to other people, who run them under their own terms and their own handling of data. Traceary has no control over what sits at the other end of an outbound link.

No guarantee

The archive is offered as it stands, with no guarantee that any page is complete, current or correct. Decisions taken on what is written here are the reader’s own. Where the answer matters, the publisher’s own page is the one to read.

Copyright

Release notes belong to the projects and companies that wrote them, and they are shown here with a link to the original on every page. Copyright and removal covers who owns what and how a rights holder asks for an entry to be taken down.

Changes and contact

The site changes, and what it says about itself changes with it. This page and the privacy page are updated before a change that affects them ships, rather than after.

Traceary is published by the person named in the imprint, who can be reached at [email protected].