Skip to content

Security: davalillo/mt5-docker

SECURITY.md

Security Policy

Overview

Security matters, even for a container project. This policy describes how to report vulnerabilities affecting mt5-docker and how they are handled.

Supported versions

Only the latest main branch and the most recent release receive security fixes. There are no backports to older versions. Please make sure you can reproduce the issue against the current main before reporting.

Reporting a vulnerability

Please report security issues privately, not as a public issue. Two channels:

  1. GitHub private vulnerability reporting (preferred). Open the Security tab of the repository and click "Report a vulnerability". This keeps the report private to the maintainers and does not expose your email address.
  2. Email fallback. Send the report to 1905197+davalillo@users.noreply.github.com. Note that this is the GitHub noreply address; for sensitive reports, prefer GitHub private reporting since it does not expose your email.

Response time

  • Acknowledgement of receipt: within 72 hours.
  • Initial assessment: within 7 days.
  • Fix timeline: depends on severity and impact. We will agree on a publication date with the reporter before any fix is released.

What to include in a report

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce, including any relevant configuration.
  • Affected versions / commits.
  • A suggested fix, if you have one.

Scope

In scope:

  • The Docker image, Dockerfile, scripts, and runtime configuration.

Out of scope (report these upstream, not here):

  • Vulnerabilities in third-party software packaged inside the image: Wine, MetaTrader 5 itself, KasmVNC, or the LinuxServer base image. Report those to their respective upstream projects.

The MetaQuotes demo account (Login=5053564303) used by this image is a free, anonymous demo account. It is not a security concern and is not in scope.

Disclosure

We ask for coordinated disclosure. Once a fix is available we will publish a security advisory and credit the reporter, unless they prefer to remain anonymous.

There aren't any published security advisories