Skip to content

Security: gewey/terminus-core

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in terminus-core, please report it responsibly:

  1. Do not open a public GitHub issue.
  2. Email: security@hobos.dev (placeholder — update with real address).
  3. Include a description of the vulnerability and a minimal reproduction if possible.

Response Timeline

  • Acknowledgment: within 48 hours.
  • Initial assessment: within 5 business days.
  • Fix or mitigation: depends on severity, typically within 30 days for high-severity issues.

Scope

This policy covers the terminus-core package itself. It does not cover Ollama, Python, or any third-party tooling you may connect to it.

There aren't any published security advisories