Skip to content

Security: cordova7/internet-computer-trading-suite

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please do not open a public GitHub issue. Instead, report it privately:

  1. Go to the repo's Security tab → Report a vulnerability, or
  2. Email the maintainer directly.

Please include:

  • A description of the issue and its potential impact
  • Steps to reproduce (proof of concept if possible)
  • Affected version / commit

We will acknowledge receipt within 72 hours and aim to send a fix or mitigation within 14 days.

Secrets Handling

  • No secrets are committed to this repository. All API tokens, bot tokens, identities, and private keys are read from environment variables at runtime (see each tool's .env.example).
  • .env files are gitignored and must never be committed.
  • If you believe a secret has been exposed, rotate it immediately with the issuing service (e.g. @BotFather for Telegram tokens) — do not rely solely on removing it from git history.

Operating on Mainnet

These tools interact with live canisters and real funds on the Internet Computer mainnet. By design they can submit transactions.

  • Always test against a local replica or testnet first.
  • Start with negligible amounts.
  • Review what a tool will submit before granting it an identity with funds.
  • The maintainers are not responsible for lost funds.

There aren't any published security advisories