TradeJS prioritizes security fixes for:
- the current default branch of each active public repository
- the currently deployed public site and docs
Older branches may receive fixes at maintainer discretion.
Do not open public issues for security reports.
If private vulnerability reporting is enabled for the affected repository, use that channel.
If it is not enabled yet, contact the maintainers privately through GitHub by messaging the organization owners or repository admins.
Please include:
- affected repository and branch
- impact and attack scenario
- reproduction steps or proof of concept
- any suggested mitigation
We will review reports, confirm severity, and coordinate a fix and disclosure plan.