If you discover a security vulnerability in any Kansoku repository, please do not open a public issue. Instead, report it privately:
- Email: i@innei.in
- Or use GitHub's private vulnerability reporting on the affected repository.
Please include:
- A description of the vulnerability and its impact.
- Steps to reproduce, or a proof of concept.
- The affected version, platform, and any relevant configuration.
You can expect an initial response within a few days. We'll keep you informed as we work on a fix, and credit you in the release notes unless you prefer to stay anonymous.
Kansoku is a local-first desktop app that talks to third-party market-data providers using your own credentials. Reports concerning credential handling, IPC/transport security, and update integrity are especially welcome.