Skip to content

Security: pineforge-4pass/pineforge-engine

SECURITY.md

Security

If you believe you have found a security vulnerability in PineForge, please report it privately rather than opening a public issue.

How to report

Use this repository’s Security tab → Report a vulnerability (GitHub Security Advisories), or contact the maintainers privately with a detailed description of the issue, affected versions, and steps to reproduce.

Please allow reasonable time for a fix before discussing the issue in public.

Scope

This repository is the PineForge engine: the C/C++ backtest runtime and native kernel, plus the optional native live runner under runner/, which reads network feeds and sends webhooks. Reports about the separate pineforge-codegen transpiler, TradingView’s platform, or third-party strategy code are out of scope for this tracker unless they concern this runtime’s build or execution of untrusted native code.

TradingView-linked CSV exports live in the public corpus/ and benchmarks/assets/ submodules and under tests/fixtures/ as factual parity references (see LEGAL.md). If you find genuinely sensitive data (secrets, credentials, private keys) committed by mistake, report it as a data-handling concern privately.

Supported versions

Security fixes are applied to the main branch as needed. Tags and release notes will note any security-relevant changes; use the latest tag where possible.

There aren't any published security advisories