Security fixes target the latest default branch state.
Do not open a public issue for security problems.
Report privately to the repository owner and include:
- impact,
- reproduction steps,
- affected files or configuration,
- relevant logs with secrets removed,
- suggested fix, if known.
Do not share:
.envfiles,- Plex tokens,
- internal media paths,
- queue payloads or logs containing private file names.
This project is maintained on a best-effort basis. Confirmed security issues are handled privately first and disclosed only after a fix or mitigation is ready.