Source, tests, docs, Pages assets, and allowlisted public JSON summaries. Credentials, broker sessions, Tushare tokens, and local market databases stay on the maintainer machine.
If you believe this public tree contains secrets, path leaks, or a way to exfiltrate non-allowlisted data from GitHub Pages:
- Do not open a public issue that repeats the secret.
- Use GitHub’s private advisory flow for fisher-admin/stock-report if available, or email the maintainer via the GitHub profile.
- Include the file path, a short reproduction, and whether Pages already served the data.
Market losses, model error, or “the signal was wrong” are not security issues.
- Run
python3 -m unittest discover tests -p 'test_*.py' -vbefore publishing. - Never commit files outside
config/public-result-allowlist.txtunderdata/. - Treat environment-variable lookups in source as allowed; literal tokens in source as a release blocker.