| Version | Supported |
|---|---|
| 1.0.x | ✅ |
If you discover a security vulnerability, please do not open a public issue. Instead, open a private security advisory on GitHub (Security → Report a vulnerability) or contact the maintainer directly.
We will respond as soon as possible and credit responsible disclosure.
- Never commit your Binance API credentials. Use
.env(gitignored) or the dashboard Config modal. - The API secret is never returned to the browser; it is stored only locally
in
data/runtime-config.json(gitignored). - Keep Enable Withdrawals disabled on your Binance API key. The bot only needs reading and trading permissions.