Only the latest minor release receives security fixes.
| Version | Supported |
|---|---|
| 0.9.x | ✅ |
| < 0.9 | ❌ |
Please report vulnerabilities privately via GitHub Security Advisories — do not open a public issue for security problems.
You can expect an acknowledgement within a week. If the report is accepted, a fix will be released as a patch version and credited to you in the changelog (unless you prefer otherwise).
- This server holds no user credentials of its own; the only secrets it
reads are optional API tokens from environment variables
(
MARKETAUX_API_TOKEN,PROXY_*). Never commit a.envfile. - All market data comes from third-party upstreams (TradingView, Yahoo Finance, Marketaux); treat tool output as informational, not as trading advice.