This repository is an academic research and reproducibility project rather than a continuously deployed production service.
| Version | Security support |
|---|---|
Current main branch |
Supported |
| Latest tagged research release | Supported on a best-effort basis |
| Superseded or audit-only analytical states | Not actively supported |
| Personal forks and modified copies | Not supported by this repository |
Security support concerns the repository's code, dependency configuration, credential handling, file processing, and distribution mechanisms. It does not imply continuing maintenance of historical empirical results.
Please do not disclose a suspected vulnerability in a public issue, discussion, pull request, commit message, or code comment.
Use GitHub's private vulnerability reporting feature through the repository's Security tab and select Report a vulnerability.
If private vulnerability reporting is temporarily unavailable, open a public issue containing only a request for a private security contact. Do not include:
- exploit code;
- credentials or tokens;
- private data;
- detailed reproduction steps;
- unpatched technical details.
A useful private report should include:
- a concise description of the issue;
- the affected file, component, or dependency;
- the potential impact;
- safe reproduction steps;
- the environment in which the issue was identified;
- any proposed mitigation;
- whether the issue has been disclosed elsewhere.
The maintainer will make a reasonable effort to:
- acknowledge a valid report within seven calendar days;
- assess its scope and severity;
- request additional information where necessary;
- prepare a correction or mitigation;
- coordinate public disclosure after a correction is available.
Response times are best-effort because this is an individually maintained academic repository.
Examples of security issues that are in scope include:
- exposed credentials, tokens, secrets, or private keys;
- unsafe handling of environment variables;
- dependency vulnerabilities affecting repository users;
- path traversal or unsafe file-writing behaviour;
- arbitrary code execution caused by repository code;
- unsafe deserialisation;
- malicious notebook or data-file execution paths;
- accidental disclosure of non-public or personal information;
- integrity weaknesses that allow frozen analytical artefacts to be silently replaced or misrepresented.
The following are not security vulnerabilities:
- disagreement with the research methodology or conclusions;
- statistical instability or lack of predictive performance;
- ordinary numerical differences between package versions;
- data-quality errors without a security impact;
- licensing or citation questions;
- requests for investment or trading advice;
- vulnerabilities that require modification of the repository by the attacker before execution;
- issues affecting unsupported forks or modified environments.
Ordinary bugs and methodological concerns should be reported through the normal issue process without including sensitive information.
Please allow a reasonable remediation period before public disclosure.
The maintainer does not currently operate a monetary bug-bounty programme. Responsible reports will be acknowledged where appropriate and where the reporter consents.
Cryptographic manifests are used for provenance and integrity verification. They do not guarantee that the underlying code, dependencies, market data, or research conclusions are free from defects.
Security corrections must not silently rewrite frozen analytical states. Historical artefacts should remain traceable, and corrected artefacts should be assigned a new documented status.
Please contact us at : contact@wavetropy.com (Baptiste DEHAY)