Security updates are applied to the latest release of Orbit.
| Version | Supported |
|---|---|
| Main | ✅ |
I take the security of Orbit seriously. If you find a vulnerability in the compiler, runtime, or Kynx, please disclose it privately rather than opening a public issue.
- Email findings: send details to
security@orbit-lang.org. - Provide details: include reproduction steps, sample
.orbcode, OS details, and potential impact. - Response time: I aim to acknowledge quickly and keep you updated on patch status. I'm solo, so if it's a weekend it can take a bit longer - I don't leave reports unread.
- Coordinated disclosure: please keep it confidential until a fix or advisory is out.
Thanks for helping keep Orbit secure - I read every report.