Security fixes are applied to the latest release on the main branch.
| Version | Supported |
|---|---|
Latest on main |
Yes |
| Older tags | Best effort |
Do not open a public GitHub issue for security vulnerabilities.
Report privately via:
- Telegram: @dexoryn (preferred)
- GitHub: Private vulnerability report if you have access
Include steps to reproduce, affected versions, and impact when possible. We aim to acknowledge reports within a few business days.
This bot handles wallets and can place real trades. Please:
- Never commit
config.yaml,targets.yaml, orsettings.yamlwith live secrets - Use
mode: dry_rununtil behavior is verified - Set
web.tokenbefore exposing the dashboard beyond localhost - Use a dedicated wallet with limited funds for automation
- Rotate API keys if they may have been exposed
Dexoryn Labs is not responsible for losses from misuse, misconfiguration, or third-party platform changes. You are responsible for securing your keys and capital.