Security fixes are provided for the latest release on the main branch.
Please do not open a public issue for a suspected vulnerability, leaked secret, or bypass of the paper/read-only boundaries.
Use GitHub's Security → Report a vulnerability flow for this repository. If private vulnerability reporting is not available, use the contact route at https://pipsync.io/en/contact and include only a minimal, non-secret summary until a private channel is established.
Include:
- affected version and file
- reproducible steps using synthetic data
- expected and actual safety boundary
- potential impact
Never include real API keys, broker credentials, customer payloads, account identifiers, or live trade data. We will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.
Security-sensitive behavior includes signature verification, replay handling, secret redaction, URL validation, body-size limits, MCP tool allowlisting, and any path that could escape loopback or paper/read-only mode.