Thanks for helping keep QuantRuntimeSettings safe.
This repository is part of the QuantStrategyLab automation, research, or trading-support surface. Please do not open a public issue for vulnerabilities involving credentials, broker or exchange access, cloud resources, workflow tokens, private market data, account identifiers, order execution, or secret material.
- Contact the maintainer directly at GitHub:
@Pigbibi. - If private vulnerability reporting is enabled for this repository, prefer that channel.
- Include the repository name, affected commit or branch, environment details, and exact reproduction steps.
- Share only the minimum logs, payloads, or screenshots needed to reproduce the issue, and redact secrets or account identifiers.
If you suspect tokens, passwords, API keys, service-account keys, cookies, broker credentials, or workflow credentials were exposed:
- Rotate the exposed secrets immediately.
- Pause scheduled jobs, deployments, or external integrations if the exposure can affect automation, artifact publishing, notifications, or trading behavior.
- Remove the exposed material from open pull requests, issues, logs, and artifacts.
- Coordinate any required history rewrite or downstream credential update with the maintainer.
- Do not use an exposed value to test, identify, or revoke a credential. Rotate from the owning provider or control plane, then update the approved secret store and verify the runtime path.
- Close a secret-scanning alert as
revokedonly after rotation and runtime verification. A history rewrite is a follow-up control, never a substitute for rotation.
- Public configuration may describe a runtime variable or secret reference, but must not contain a production notification target, account identifier, token, or credential value.
- Every public
notifications.*.telegram_chat_id_reffollows the canonical cross-platform contract: runtime prefersQSL_GLOBAL_TELEGRAM_CHAT_IDand can fall back to the documented compatibility variables. Config validation rejects a rawtelegram_chat_idfor every notification entry, including future strategy plugins. - Runtime resource names and workflow topology are not credentials. Keep them accurate for reproducible operations; migrate only values that are not required by public build or deployment contracts.
Security fixes should stay minimal and focused. Please avoid bundling unrelated refactors, formatting churn, research changes, or feature work with a security report or patch.