Orchard is a fast-moving project. Security fixes are made against the latest
release, so please make sure you're on the most recent version (via
brew upgrade --cask orchard or the latest release)
before reporting an issue.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately using GitHub's Report a vulnerability button under the repository's Security tab. This opens a private advisory visible only to the maintainers.
When reporting, please include as much of the following as you can:
- A description of the issue and its potential impact.
- Steps to reproduce (a proof of concept is ideal).
- The Orchard version, macOS version, and
containerversion. - Any suggested remediation, if you have one.
- We aim to acknowledge reports within a few days.
- We'll keep you updated on our assessment and a fix timeline.
- Once a fix is released, we're happy to credit you in the advisory and release notes (unless you'd prefer to remain anonymous).
Thank you for helping keep Orchard and its users safe.