Skip to content

Security: dudujuju828/SpecOrca

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in SpecOrca, please report it responsibly. Do not open a public GitHub issue.

Instead, email the maintainers directly or use GitHub's private vulnerability reporting feature on this repository.

Please include:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce or a proof-of-concept.
  • The version(s) of SpecOrca affected.

Response timeline

  • Acknowledgement within 3 business days.
  • Assessment and fix as soon as practical; we aim to release a patch within 14 days for confirmed vulnerabilities.

Supported versions

Version Supported
0.1.x Yes

Scope

This policy covers the SpecOrca Python package (spec_orca) and its default Claude Code backend integration. Third-party backends are outside this scope — please report issues with those to their respective maintainers.

There aren’t any published security advisories