Skip to content

Security: ZilaiWang/TermKit

SECURITY.md

Security policy

Please do not open public issues for vulnerabilities involving archive path handling, checksum verification, plugin loading, registry integrity, source privacy, or license-gate bypasses.

Until a dedicated security address is configured, use GitHub private vulnerability reporting on the eventual project repository. Include affected version, minimal reproduction, impact, and suggested mitigation when possible.

The optional HTTP adapter is not a production multi-tenant service. Reports that only demonstrate missing authentication on an explicitly local adapter are out of scope unless they show an undocumented remote exposure.

See docs/security.md for the trust model.

There aren't any published security advisories