Skip to content

Security: orchidsoftware/charts

Security

SECURITY.md

Security policy

Supported versions

Version Supported
1.0.x Yes
< 1.0 No

Reporting a vulnerability

Do not open a public issue or include an exploit in a pull request. Once the GitHub repository exists, enable private vulnerability reporting and use its security advisory form. Until that channel exists, report the problem privately to the maintainer through the contact method listed on the maintainer's GitHub profile.

Include the affected version, impact, reproduction, and any suggested mitigation. Expect an acknowledgement within three business days and an initial assessment within seven. Release timing depends on severity and the need to coordinate downstream updates. Credit is offered unless the reporter prefers to remain anonymous.

There aren't any published security advisories