Skip to content

Security: baptiste-dehay/fractal-financial-markets-elliott-wave-validation

SECURITY.md

Security Policy

Supported Versions

This repository is an academic research and reproducibility project rather than a continuously deployed production service.

Version Security support
Current main branch Supported
Latest tagged research release Supported on a best-effort basis
Superseded or audit-only analytical states Not actively supported
Personal forks and modified copies Not supported by this repository

Security support concerns the repository's code, dependency configuration, credential handling, file processing, and distribution mechanisms. It does not imply continuing maintenance of historical empirical results.

Reporting a Vulnerability

Please do not disclose a suspected vulnerability in a public issue, discussion, pull request, commit message, or code comment.

Use GitHub's private vulnerability reporting feature through the repository's Security tab and select Report a vulnerability.

If private vulnerability reporting is temporarily unavailable, open a public issue containing only a request for a private security contact. Do not include:

  • exploit code;
  • credentials or tokens;
  • private data;
  • detailed reproduction steps;
  • unpatched technical details.

A useful private report should include:

  • a concise description of the issue;
  • the affected file, component, or dependency;
  • the potential impact;
  • safe reproduction steps;
  • the environment in which the issue was identified;
  • any proposed mitigation;
  • whether the issue has been disclosed elsewhere.

Response Process

The maintainer will make a reasonable effort to:

  1. acknowledge a valid report within seven calendar days;
  2. assess its scope and severity;
  3. request additional information where necessary;
  4. prepare a correction or mitigation;
  5. coordinate public disclosure after a correction is available.

Response times are best-effort because this is an individually maintained academic repository.

In Scope

Examples of security issues that are in scope include:

  • exposed credentials, tokens, secrets, or private keys;
  • unsafe handling of environment variables;
  • dependency vulnerabilities affecting repository users;
  • path traversal or unsafe file-writing behaviour;
  • arbitrary code execution caused by repository code;
  • unsafe deserialisation;
  • malicious notebook or data-file execution paths;
  • accidental disclosure of non-public or personal information;
  • integrity weaknesses that allow frozen analytical artefacts to be silently replaced or misrepresented.

Out of Scope

The following are not security vulnerabilities:

  • disagreement with the research methodology or conclusions;
  • statistical instability or lack of predictive performance;
  • ordinary numerical differences between package versions;
  • data-quality errors without a security impact;
  • licensing or citation questions;
  • requests for investment or trading advice;
  • vulnerabilities that require modification of the repository by the attacker before execution;
  • issues affecting unsupported forks or modified environments.

Ordinary bugs and methodological concerns should be reported through the normal issue process without including sensitive information.

Coordinated Disclosure

Please allow a reasonable remediation period before public disclosure.

The maintainer does not currently operate a monetary bug-bounty programme. Responsible reports will be acknowledged where appropriate and where the reporter consents.

Security of Research Artefacts

Cryptographic manifests are used for provenance and integrity verification. They do not guarantee that the underlying code, dependencies, market data, or research conclusions are free from defects.

Security corrections must not silently rewrite frozen analytical states. Historical artefacts should remain traceable, and corrected artefacts should be assigned a new documented status.

Please contact us at : contact@wavetropy.com (Baptiste DEHAY)

There aren't any published security advisories