Skip to content

Security: pipsyncio/pipsync-examples

SECURITY.md

Security policy

Supported versions

Security fixes are provided for the latest release on the main branch.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability, leaked secret, or bypass of the paper/read-only boundaries.

Use GitHub's Security → Report a vulnerability flow for this repository. If private vulnerability reporting is not available, use the contact route at https://pipsync.io/en/contact and include only a minimal, non-secret summary until a private channel is established.

Include:

  • affected version and file
  • reproducible steps using synthetic data
  • expected and actual safety boundary
  • potential impact

Never include real API keys, broker credentials, customer payloads, account identifiers, or live trade data. We will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.

Scope

Security-sensitive behavior includes signature verification, replay handling, secret redaction, URL validation, body-size limits, MCP tool allowlisting, and any path that could escape loopback or paper/read-only mode.

There aren't any published security advisories