Last updated
Security Policy
Supported Versions
Until OpenCandle reaches 1.0.0, security support is limited to the latest pre-1.0 release line.
| Version | Supported |
|---|---|
Latest 0.x release |
Yes |
| Older pre-1.0 releases | No |
| Unreleased local forks | No |
Reporting a Vulnerability
Do not open public GitHub issues for security vulnerabilities.
Do not include API keys, provider tokens, account identifiers, personal holdings screenshots, full ~/.opencandle state, or unredacted local paths in public reports, screenshots, logs, or traces.
Use the repository's private vulnerability reporting (GitHub Security Advisories) to report suspected vulnerabilities to the maintainers. If GitHub private reporting is unavailable to you, open a minimal public issue that says you need a private security contact without including exploit details or sensitive data.
When reporting an issue, include:
- affected version or commit
- impact summary
- reproduction steps or proof of concept
- any suggested mitigation if known
Maintainers aim to acknowledge valid reports within 7 days, investigate them privately, and coordinate a fix and release before public disclosure when practical.