The Terravic organization takes software security, data protection, and vulnerability management very seriously. We appreciate the responsible disclosure of vulnerabilities by security researchers and community members.
Security updates are prioritized for the latest minor release of each active project. Unless otherwise stated in a project-specific repository, support levels follow this matrix:
| Release Status | Supported |
|---|---|
Latest Default Branch (main) |
Yes |
| Latest Semantic Tag / Release | Yes |
| Legacy / Deprecated Releases | No |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
If you discover a vulnerability, misconfiguration, or security flaw in any Terravic repository, report it through one of the following private channels:
-
GitHub Private Security Advisory (Preferred):
- Navigate to the target repository on GitHub.
- Click the Security tab.
- Select Advisories, then click Report a vulnerability to open a private advisory draft directly with the maintainers.
-
Direct Security Contact:
- If private advisories are unavailable, send an email detailing the findings to: security@terravic.dev (or contact the organization administrators directly).
To help us triage and resolve the issue quickly, please include as much of the following information as possible:
- The repository name and affected version or commit SHA.
- A clear description of the vulnerability and its potential impact.
- Step-by-step reproduction instructions or a minimal Proof of Concept (PoC).
- Any existing mitigations or proposed patches, if available.
- Any known public disclosure timelines or disclosure dependencies.
- Acknowledgment: We aim to acknowledge receipt of security reports within 48 hours.
- Assessment: We will validate the issue, determine its severity, and provide an initial response with next steps within 5 business days.
- Remediation: Once confirmed, a fix will be developed, tested, and released as a priority security patch.
- Coordination: We ask that reporters maintain confidentiality and avoid public disclosure until an official fix or advisory has been published.