Security fixes target the latest patch in the latest released minor series. Older minor series are unsupported unless a release note explicitly states otherwise. Upgrade to the latest published version before reporting an issue that may already be fixed.
Do not open a public issue for a vulnerability, exposed credential, or private dataset. Email
Artur Sepp at artursepp@gmail.com with:
- the affected version or commit;
- a minimal reproduction or description of the attack path;
- the likely impact; and
- any suggested mitigation.
Remove credentials, licensed market data, and personal information from the report whenever possible. Receipt should be acknowledged within seven days. A fix and disclosure timeline will be coordinated according to severity and the availability of a safe release.
This policy covers OCA code and packaging. Provider outages, provider credentials, dataset licences, and vulnerabilities in third-party services should also be reported to their respective owners.