Skip to content

Security: xscriptor/terax

Security

SECURITY.md

Security Policy


Reporting a Vulnerability

If you discover a security vulnerability in the theme files, install scripts, or repository configuration, please report it privately to:

x@xscriptor.com

Please include:

  • A clear description of the issue
  • Steps to reproduce or a proof of concept
  • Affected versions or commit ranges
  • Any suggested mitigations

Do not open a public issue for security vulnerabilities.


Supported Versions

Version Supported
1.0.x Yes
< 1.0 No

Only the latest major version receives security updates.


Disclosure Timeline

  1. Reporter submits vulnerability via email.
  2. Maintainer acknowledges receipt within 48 hours.
  3. Maintainer validates and assesses the issue within 5 business days.
  4. A fix is prepared and released. The reporter is notified of the planned release date.
  5. After the fix is released, a public advisory may be published at the maintainer's discretion.

Scope

This security policy applies to the Terax Themes repository only:

  • Theme JSON files in themes/
  • Install scripts (install-terax-themes.sh, install-terax-themes.ps1)
  • Repository configuration and GitHub Actions workflows

Issues in the Terax application itself should be reported to the upstream project at crynta/terax-ai.

There aren't any published security advisories