Security fixes target the current main branch. Older commits and forks do not receive separate maintenance. Until releases are published, include the exact commit SHA when reporting a problem.
Use GitHub's private vulnerability reporting form. If private reporting is unavailable, ask the repository owner for a private reporting channel without posting vulnerability details in a public issue.
Include the affected commit, component, MT5/MetaEditor build or language runtime, prerequisites, expected security boundary, observed impact, and a minimal reproducible example. Use synthetic data where possible. Do not send passwords, API tokens, account numbers, private broker data, or personal information.
Please allow maintainers to investigate and coordinate a fix before publicly disclosing exploitation details. Response and resolution times depend on maintainer availability; this project does not promise a service-level agreement or a bounty.
Ordinary detection errors, build failures, and documentation issues belong in the issue tracker. A trading loss alone is not evidence of a security vulnerability; describe the concrete software behavior and impact.