StockAnalyzer is an open-source tool primarily developed and maintained using AI coding assistants. As noted in the README, the project does not have a traditional dedicated team of human maintainers or security staff.
Consequently, we do not have a private vulnerability disclosure channel (such as a security email).
If you discover a security vulnerability, please follow these guidelines:
- Local Resolution: Since the project is AI-driven, users are highly encouraged to utilize AI coding assistants (such as Gemini, Copilot, etc.) to investigate, patch, and harden the security of their local installations.
- Public Contributions: If you have developed a security patch, please feel free to submit a public Pull Request (PR) with the fix so that all users can benefit from the improvement.
- No Warranty: As stated in the license (MIT) and README warnings, this software is provided "as-is" without warranty of any kind. You are responsible for auditing the code and ensuring its safety in your own environment.