Thank you for helping keep Termal OS and its users safe.
Please do not open a public issue for security problems. Public disclosure before a fix puts users at risk.
Report privately, one of two ways:
- GitHub private reporting (preferred): open the Security tab of any TermalOS repository and click "Report a vulnerability". This starts a private advisory visible only to you and the maintainer.
- Email: write to hello@termalos.com with
[Security]in the subject.
Please include:
- what the issue is and its impact,
- clear steps to reproduce (or a proof of concept),
- the Termal OS version and your operating system,
- any relevant logs, with secrets removed.
Termal OS is a solo project, so responses are best effort, but security is a priority:
- acknowledgement within 72 hours,
- an assessment and a plan within 7 days,
- a fix shipped as fast as reasonably possible, with credit to you if you want it (staying anonymous is fine too).
Please allow reasonable time to fix an issue before any public disclosure. We will not pursue legal action over good faith security research that respects this policy and does not harm users or their data.
In scope: the Termal OS desktop application, its update mechanism, the license API, and the termalos.com website.
Out of scope: issues that require an already compromised machine, social engineering, and automated scanner output without a demonstrated impact.
During the Preview, only the latest published release is supported. Please update before reporting.