Do not open a public issue, discussion, or pull request for a suspected vulnerability.
- Open the affected repository's Security tab.
- Choose Report a vulnerability to start a private security advisory.
- If private reporting is unavailable, contact PipSync through the official support channel and ask for a private security-reporting channel. Do not include secrets or exploit details in an initial public message.
Include only what is necessary to reproduce and assess the issue:
- affected repository, release, commit, or API version
- impact and prerequisites
- minimal reproduction using synthetic data
- relevant request/response metadata with tokens and identifiers removed
- suggested mitigation, if known
Never send API keys, webhook secrets, broker credentials, session cookies, customer signals, account numbers, or unredacted logs. PipSync will acknowledge receipt through the private channel and coordinate remediation and disclosure there. Response and remediation time depend on severity and reproducibility; this policy makes no fixed service-level commitment.
Reports about code in a public repository are in scope when they affect the latest release or the default branch. Product-service vulnerabilities may also be reported through the same private process.
The following are generally out of scope unless they demonstrate a concrete security impact:
- missing hardening headers without an exploitable condition
- rate-limit observations that do not affect availability or authorization
- social engineering, physical attacks, or denial-of-service testing
- attacks against third-party systems or accounts you do not own
- findings from automated scanners without a reproducible impact
Do not access other users' data, place live trades, degrade a service, or retain sensitive data while researching. Use mock, synthetic, paper, or accounts you are explicitly authorized to test.
Security fixes are made on the latest supported release line and the default branch. Older releases may require an upgrade. Each repository may publish a more specific support matrix that overrides this default.
PipSync intends not to pursue action against good-faith research that follows this policy, stays within authorized systems, avoids privacy or service harm, and gives reasonable time for remediation before disclosure. This statement is not a waiver of third-party rights or applicable law.