Terrence follows a rolling-release model on master. The latest tagged release and master receive security fixes.
Please report suspected security vulnerabilities privately rather than via public issues or discussions.
You can report vulnerabilities through either of the following channels:
- GitHub Security Advisories (Recommended): Submit a private report at GitHub Advisory Submission.
- Email: Contact the security team directly at security@essinghigh.org.
When reporting a vulnerability, please include:
- A description of the issue and its potential security impact
- Steps to reproduce or proof-of-concept code
- Affected components or versions
We follow coordinated vulnerability disclosure practices:
- Response: We acknowledge receipt of any vulnerability report within 3 days.
- Assessment & Confirmation: We investigate and validate the report within 30 days.
- Remediation & Coordinated Disclosure: We aim to release a patch and publish a security advisory within 90 days of confirmation, coordinating the disclosure date with the reporter.
This policy covers the Terrence server, the frontend, and the terrance-agent client. Supply-chain vulnerabilities in third-party dependencies should be reported upstream to the respective maintainers, or to us when they affect how Terrence consumes them.