Please do not open a public issue for vulnerabilities involving privileged helpers, HID access, command execution, profile import, or package integrity.
Report vulnerabilities privately through GitHub's security advisory form. Include reproduction steps, affected versions, and the expected impact.
Orbit is an early-stage project. Security fixes are prioritized for the latest release; older releases may not receive backports.