keel holds exchange API credentials and places live orders. Once strangers read the source, someone will eventually find a way to make it misbehave — and there is currently no private channel to report it. The only options are a public issue (which discloses it to everyone simultaneously) or nothing.
Acceptance
Note
Enable GitHub's private vulnerability reporting in repo settings at the same time; the file alone gives no channel.
keel holds exchange API credentials and places live orders. Once strangers read the source, someone will eventually find a way to make it misbehave — and there is currently no private channel to report it. The only options are a public issue (which discloses it to everyone simultaneously) or nothing.
Acceptance
SECURITY.mdat repo rootNote
Enable GitHub's private vulnerability reporting in repo settings at the same time; the file alone gives no channel.