Skip to content

Security: gustavosmede/OpenGEX

Security

SECURITY.md

Security policy

Please do not publish API keys, secrets, authorization headers, private snapshots, or other sensitive market-data artifacts in issues or pull requests.

For a suspected security issue, contact the repository owner privately through GitHub rather than opening a public issue. Include a concise description, reproduction steps that do not contain secrets, and the affected revision.

The application reads Alpaca credentials from environment variables or an ignored local environment file. Credentials must never be logged or committed.

There aren't any published security advisories