| Version | Supported |
|---|---|
| 0.9.x | Yes |
| 0.8.x | Yes |
| 0.7.x | Yes |
| 0.6.x | Yes |
| 0.5.x | Yes |
If you discover a security vulnerability, please do not open a public issue. Instead, please open a private security advisory or contact the maintainer directly.
We ask that you:
- Give us reasonable time to investigate and fix the issue before public disclosure.
- Provide enough detail to reproduce the vulnerability.
- Do not access or modify data that does not belong to you.
We will acknowledge your report within 48 hours and aim to provide a fix within 7 days for confirmed vulnerabilities.
- This project connects to Futu OpenD via a local TCP socket. Ensure your OpenD instance is not exposed to untrusted networks.
- Trading operations in the demo require an unlocked trading account. Never run the demo on a production account without proper safeguards.
- Do not share your Futu API credentials or trade password in any public forum.
- Do not commit
.envfiles or any files containing credentials to the repository.