Skip to content

Security: andrew-waters/orchard

Security

SECURITY.md

Security Policy

Supported versions

Orchard is a fast-moving project. Security fixes are made against the latest release, so please make sure you're on the most recent version (via brew upgrade --cask orchard or the latest release) before reporting an issue.

Version Supported
Latest release
Older releases

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, report them privately using GitHub's Report a vulnerability button under the repository's Security tab. This opens a private advisory visible only to the maintainers.

When reporting, please include as much of the following as you can:

  • A description of the issue and its potential impact.
  • Steps to reproduce (a proof of concept is ideal).
  • The Orchard version, macOS version, and container version.
  • Any suggested remediation, if you have one.

What to expect

  • We aim to acknowledge reports within a few days.
  • We'll keep you updated on our assessment and a fix timeline.
  • Once a fix is released, we're happy to credit you in the advisory and release notes (unless you'd prefer to remain anonymous).

Thank you for helping keep Orchard and its users safe.

There aren't any published security advisories