Skip to content

Security: echoVic/orca-agent

SECURITY.md

Security Policy

Supported Versions

Only the latest released version receives security updates.

Version Supported
Latest release Yes
Older releases No

Reporting a Vulnerability

Report vulnerabilities privately through a GitHub security advisory. Do not open a public Issue.

Please include:

  • The affected version and platform.
  • The impact and attack scenario.
  • A minimal reproduction or proof of concept.
  • Affected files, commands, or protocol surfaces.
  • Any known mitigations or workarounds.
  • Whether the issue has been disclosed previously, and to whom.

Remove API keys, tokens, private source code, personal data, and sensitive logs from the report.

The project does not promise a fixed response SLA. Reporters and maintainers are asked to coordinate validation, remediation, and disclosure so users have time to update before technical details are published.

There aren't any published security advisories