Security fixes are applied to the latest release line.
Do not open a public issue for a security vulnerability.
Send a private report to the project maintainer after the repository is published. If you fork this repository, replace this section with your own security contact.
A useful report includes:
- Affected version or commit
- Operating system
- Reproduction steps
- Expected behavior
- Actual behavior
- Impact
- Suggested fix, if known
Orion avoids telemetry, automatic network calls, extension execution, and shell-based command execution by default. See docs/SECURITY_MODEL.md for details.