Last Updated / Effective Date: September 24th, 2026
Do not report security vulnerabilities through GitHub issues, pull requests, discussions, social media, or other public channels.
If you believe you have discovered a security vulnerability in Orbit, please report it privately by emailing IT@planetaryapp.us.
When possible, include:
- A clear description of the vulnerability.
- The affected component or version.
- Steps to reproduce the issue.
- The potential impact or attack scenario.
- Proof-of-concept material, if applicable.
- Suggested mitigation or remediation.
- Any other information that may help us investigate the issue.
Please remove unrelated personal information, credentials, API keys, tokens, passwords, and other secrets from your report. Do not include secrets that are not necessary to demonstrate the vulnerability.
Before submitting a report, please verify that the issue still exists in the newest available version of Orbit. When possible, test against the newest beta build as well as the latest stable release.
If the vulnerability is no longer present in the newest versions, please mention the version in which you verified the issue and, if known, the version where the issue was fixed.
We ask that security vulnerabilities remain private until Orbit's maintainers have had an opportunity to investigate and address them.