If you discover a security vulnerability in terminus-core, please report it
responsibly:
- Do not open a public GitHub issue.
- Email: security@hobos.dev (placeholder — update with real address).
- Include a description of the vulnerability and a minimal reproduction if possible.
- Acknowledgment: within 48 hours.
- Initial assessment: within 5 business days.
- Fix or mitigation: depends on severity, typically within 30 days for high-severity issues.
This policy covers the terminus-core package itself. It does not cover
Ollama, Python, or any third-party tooling you may connect to it.