Please do not open a public issue for a suspected vulnerability or an accidentally exposed secret. Use GitHub's private vulnerability reporting for this repository.
Never include API keys, webhook secrets, broker credentials, real account identifiers, or customer payloads in a report. Replace them with synthetic values and rotate any value that may have been exposed.
Supported security fixes target the latest release. This project is paper-only educational tooling and must not be treated as a live-trading control.