Skip to content

Security: essinghigh-org/terrence

SECURITY.md

Security Policy

Supported Versions

Terrence follows a rolling-release model on master. The latest tagged release and master receive security fixes.

Reporting a Vulnerability

Please report suspected security vulnerabilities privately rather than via public issues or discussions.

You can report vulnerabilities through either of the following channels:

When reporting a vulnerability, please include:

  • A description of the issue and its potential security impact
  • Steps to reproduce or proof-of-concept code
  • Affected components or versions

Disclosure Process & Timeline

We follow coordinated vulnerability disclosure practices:

  1. Response: We acknowledge receipt of any vulnerability report within 3 days.
  2. Assessment & Confirmation: We investigate and validate the report within 30 days.
  3. Remediation & Coordinated Disclosure: We aim to release a patch and publish a security advisory within 90 days of confirmation, coordinating the disclosure date with the reporter.

Scope

This policy covers the Terrence server, the frontend, and the terrance-agent client. Supply-chain vulnerabilities in third-party dependencies should be reported upstream to the respective maintainers, or to us when they affect how Terrence consumes them.

There aren't any published security advisories