Security fixes are applied to the latest release only. Older tags do not receive backported patches. Please upgrade to the most recent version before reporting an issue.
| Version | Supported |
|---|---|
| Latest | ✅ |
| Older | ❌ |
Please do NOT open a public issue for security vulnerabilities.
Preferred: use GitHub's built-in private vulnerability reporting. Open the repository's Security tab and click Report a vulnerability under Advisories. This is the primary channel on the public repository and needs no email address.
Fallback: if the Security tab is not available to you (for example while the repository is private, where it is reachable only by collaborators), email github-admins@emkraan.com.
Include as much detail as you can either way:
- a description of the vulnerability and its impact,
- the affected version or image tag,
- clear steps to reproduce (a proof of concept if available),
- any suggested remediation.
- We aim to acknowledge new reports within a few days.
- We will work with you privately to confirm, triage, and fix the issue.
- Once a fix is available and released, the advisory is published and credit is given to the reporter unless anonymity is requested.
Thank you for helping keep Snagarr and its users safe.