Skip to content

Security: DepthSight-Pro/DepthSight

Security

SECURITY.md

Security Policy

Supported Versions

Currently, only the latest commit on the main branch is actively supported with security updates.

Version Supported
main
Older

Reporting a Vulnerability

DepthSight takes security issues very seriously, especially given the financial nature of algorithmic trading and API key management.

If you discover a security vulnerability within DepthSight, please DO NOT open a public issue or discussion. Instead, we ask that you privately report the issue to us to allow a safe coordinated disclosure and patch.

How to Report

Please send an email to: admin@depthsight.pro

Include the following information in your report:

  • Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, logic flaw).
  • Full paths of source file(s) related to the manifestation of the issue.
  • The location of the affected source code (tag/branch/commit or direct URL).
  • Any special configuration required to reproduce the issue.
  • Step-by-step instructions to reproduce the issue.
  • Proof-of-concept or exploit code (if possible).
  • Impact of the issue, including how an attacker might exploit the issue.

Response and Remediation

We will endeavor to respond to your report within 48 hours.

If the vulnerability is confirmed, we will work on a patch, release an update, and publicly acknowledge your contribution (if you desire) once the patch has been made available to the community.

There aren't any published security advisories