Skip to content

Security: velteyn/EclipseTrader

SECURITY.md

Security Policy

Supported Versions

The following table summarizes the security support status for different versions of EclipseTrader. As an open-source project maintained by a small team, we focus our efforts on the most recent releases.

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

We take security vulnerabilities seriously. We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.

To report a vulnerability, please open a new issue or start a private discussion on our GitHub repository. Please provide a detailed description of the issue, the steps to reproduce it, and the affected version.

What to Expect:

  • You will receive an acknowledgment of your report within 48 hours.
  • We will provide an initial assessment of the vulnerability's severity and impact within 72 hours.
  • We will keep you informed of the progress towards a fix and may ask for additional information.
  • Once a fix is developed, we will coordinate with you on the public disclosure.

We kindly ask that you do not disclose the vulnerability publicly until a patch has been released.

There aren't any published security advisories