Security fixes are handled on the default branch. Older local copies and forks should pull the latest default branch before reporting an issue as unresolved.
Please do not open a public issue with exploit details, secrets, credentials, or private market data.
Use GitHub private vulnerability reporting if it is available for this repository. If private reporting is not available, open a minimal public issue asking for a maintainer contact and omit sensitive details.
Useful reports include:
- Affected command, route, or file path
- Steps to reproduce using sample data when possible
- Expected and actual behavior
- Impact and any known workaround
In scope:
- Secret exposure risks
- Path traversal, arbitrary file read/write, or unsafe file handling
- Dashboard or API vulnerabilities
- Dependency vulnerabilities with a practical impact on this project
Out of scope:
- Trading performance, profitability, or model accuracy claims
- Vulnerabilities requiring leaked local credentials
- Denial-of-service cases that require unrealistic local machine access
RLER is paper-only. Do not add broker credentials to config files, issues, pull requests, logs, screenshots, or sample data.