Skip to content

Security: jcll/movie-night

SECURITY.md

Security policy

Supported version

Security fixes are provided for the latest released version of Movie Night. Older releases and unreleased development snapshots are not separately supported.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting form so the report and any sensitive reproduction details remain private.

Include the affected version, deployment shape, impact, reproduction steps, and any suggested mitigation you can safely provide. Remove Plex tokens, cookies, proxy secrets, private media paths, hostnames, and personal data from logs or screenshots before attaching them.

Reports are reviewed and answered on a best-effort basis. There is no promised response or remediation timeline, but good-faith reports are welcome. Please allow time for a fix and coordinated disclosure before publishing details.

Scope reminders

Anonymous access to the viewer page, sanitized room state, room WebSocket, and authorized media is intentional. Catalog access, preparation, playback control, and administration must remain authenticated and server-authorized. Reports that cross those boundaries, expose credentials or private paths, or bypass room/media-generation authorization are especially useful.

There aren't any published security advisories