Security fixes are applied to the latest release on the default branch.
| Version | Supported |
|---|---|
| 0.1.x | Yes |
| Earlier | No |
Use the repository's Security tab to submit a private vulnerability report. Do not open a public issue for a suspected vulnerability. If private reporting is unavailable, use the PipSync support channel and request a private security contact before sharing technical details.
Include the affected version, browser, reproduction steps, likely impact, and any safe remediation idea. Do not include API keys, webhook secrets, account IDs, customer payloads, private URLs, production logs, or live broker data.
This repository is a static site with no server, database, authentication, live API client, broker connector, or order execution. Its Content Security Policy blocks runtime network connections. The HMAC example uses a fixed public demo key that is not a credential.
Relevant reports include script injection, a path that unexpectedly transmits input, unsafe clipboard handling, schema-validator bypasses, arithmetic that can overstate a safe rounded size, deployment workflow compromise, or a misleading live-execution affordance.
Requests for financial advice, live trading support, performance guarantees, or disclosure of private production internals are out of scope.