Skip to content

Security: mlgorithm/orchid-ranker

Security

SECURITY.md

Security Policy

Supported Releases

Orchid Ranker is a maintained Python library rather than a hosted service. Security fixes are considered for the latest published stable release and the active development branch. Users of older releases should upgrade before opening a report whenever possible.

Reporting a Vulnerability

Please report suspected vulnerabilities privately to sam.urmian@gmail.com with the subject [orchid-ranker security]. Do not open a public GitHub issue until the maintainer has had an opportunity to investigate and coordinate disclosure.

Include, when available:

  • the affected Orchid Ranker version and installation method;
  • a minimal reproduction or proof of concept;
  • the impact you observed or expect; and
  • any relevant environment details.

Redact credentials, learner data, access tokens, and other confidential information. The project does not publish a response-time guarantee; reports will be handled as promptly as the maintainer can manage.

Scope

This policy covers the Orchid Ranker source repository, released Python distributions, and project-managed GitHub Actions workflows. For ordinary bugs and feature requests, use the issue tracker.

There aren't any published security advisories