Security fixes are applied to the latest release on the main branch. We recommend always running the most recent version from orbiteditorai.com.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
If you discover a security issue in Orbit, report it privately to:
Include as much detail as possible:
- Description of the vulnerability and its potential impact
- Steps to reproduce
- Affected version or commit
- Any proof-of-concept code (if applicable)
We aim to acknowledge reports within 3 business days and will keep you informed of our progress.
- We confirm receipt and assess the report.
- We work on a fix on a private branch when warranted.
- We coordinate disclosure timing with you.
- We publish a patched release and credit you (unless you prefer to remain anonymous).
This policy covers the Orbit desktop editor in this repository (orbiteditor).
Out of scope:
- Third-party LLM provider APIs (report those to the respective provider)
- VS Code upstream vulnerabilities already tracked by Microsoft (report to microsoft/vscode)
- Social engineering or physical attacks
We support good-faith security research. Do not access data that is not yours, degrade service for other users, or publicly disclose issues before we have had a reasonable chance to address them.
Thank you for helping keep Orbit and its users safe.