Skip to content

Security: scottgigawatt/plundarr

docs/SECURITY.md

Security policy πŸ›‘οΈπŸ΄β€β˜ οΈ

Ahoy, security-minded sailor. If ye spot a cursed leak, a leaky hull, or a suspicious barnacle clingin' to Plundarr, this be the proper chart for reportin' it.

Supported versions βš“

Plundarr sails mostly by the main branch. Since this project be a small vessel, security fixes target the newest chart instead of older treasure maps.

Version Supported
main branch βœ…
Older local copies ❌
Forked or modified PIA scripts ❌

Important

🧭 Plundarr consumes the published Privateerr image for PIA WireGuard config and port-forwarding metadata. Privateerr uses upstream PIA manual connection scripts, and issues in those scripts should also be reported to the PIA project.

Report a vulnerability 🦜

Please do not open a public GitHub issue for secrets, credential leaks, auth bypasses, or anything that could help another scallywag attack a user.

Report vulnerabilities using GitHub's private vulnerability reporting feature:

  1. Go to the repository's Security tab.
  2. Choose Report a vulnerability.
  3. Include clear steps to reproduce, affected files, logs, image tags, and any relevant Docker Compose settings.

Do not send vulnerability details through Discord, discussions, issues, or pull requests. Those routes are for non-sensitive support and public collaboration.

If private vulnerability reporting is unavailable, open a GitHub issue containing only a brief, non-sensitive request for a private reporting channel. Do not describe the vulnerability publicly.

Include useful evidence πŸ“œ

Helpful reports include:

  • What ye found.
  • How to reproduce it.
  • What branch, image tag, or commit ye tested.
  • Whether it affects Plundarr Compose wiring, PIA WireGuard, port forwarding, Privateerr integration, Gluetun integration, or another service.
  • Any safe logs with secrets removed.

Warning

πŸ’£ Never include real usernames, passwords, WireGuard private keys, generated wg0.conf files, forwarded ports, or live privateerr.env metadata in a public report.

Understand response expectations πŸ•°οΈ

This be a small maintainer ship, not a giant navy. I will do my best to:

  • Acknowledge valid private reports within 7 days.
  • Triage severity and scope as soon as possible.
  • Patch accepted issues in main.
  • Credit reporters when requested and safe to do so.

If a report is declined, I will try to explain why without leakin' dangerous details into open waters.

Understand stack security πŸ”Ž

Plundarr pulls published container images for the stack and keeps configuration in service-specific directories. Pull updated stable images regularly so accepted security fixes reach the deployment.

Use the support guide for non-sensitive setup questions and reproducible bugs.

Fair winds, sharp eyes, and may yer secrets stay below deck. ☠️

There aren't any published security advisories