Security fixes are provided for the latest stable release of each OrbitGraph package.
| Version | Supported |
|---|---|
1.x |
Yes |
< 1.0.0 |
No |
Please do not report security vulnerabilities through public GitHub issues, discussions, pull requests, or social media.
Report suspected vulnerabilities privately by email:
orbitgraph.maintainers@gmail.com
If you have not created this project email address yet, replace it with the maintainer contact address before committing this file.
Include as much of the following information as possible:
- A clear description of the vulnerability.
- Affected OrbitGraph package and version.
- Steps to reproduce the issue.
- Potential impact.
- A proof of concept, if available.
- Suggested mitigation or fix, if you have one.
- An acknowledgement within 7 days.
- A follow-up after initial triage when more information is needed.
- A fix or mitigation timeline after the issue is confirmed.
- Credit in the release notes when requested and appropriate.
Please allow reasonable time for a fix before publicly disclosing a confirmed vulnerability.
This policy covers the official OrbitGraph packages and repository:
@orbitgraph/core@orbitgraph/three@orbitgraph/react- The OrbitGraph GitHub repository and official examples
Third-party applications built with OrbitGraph are outside this policy unless the issue is directly caused by official OrbitGraph code.